W3C home > Mailing lists > Public > public-web-security@w3.org > December 2009

Re: Seamless iframes + CSS3 selectors = bad idea

From: Ian Hickson <ian@hixie.ch>
Date: Sun, 6 Dec 2009 09:27:08 +0000 (UTC)
To: "sird@rckc.at" <sird@rckc.at>
Cc: Maciej Stachowiak <mjs@apple.com>, Adam Barth <w3c@adambarth.com>, public-web-security@w3.org
Message-ID: <Pine.LNX.4.62.0912060926130.5629@hixie.dreamhostps.com>
On Sun, 6 Dec 2009, sird@rckc.at wrote:
> I understood only members/invited.experts had a real vote in it..

HTML5, as a work product of both the WHATWG and the HTMLWG, is a 
completely open project with full participation possible from anyone.

> wrt autofocus it enables xss vectors without user interaction (Mario 
> Heiderich/Gareth Heyes).

I encourage you to send your comments to one of the lists given in the 
spec's "status of this document" section.

Ian Hickson               U+1047E                )\._.,--....,'``.    fL
http://ln.hixie.ch/       U+263A                /,   _.. \   _\  ;`._ ,.
Things that are impossible just take longer.   `._.-(,_..'--(,_..'`-.;.'
Received on Sunday, 6 December 2009 09:27:37 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Sunday, 19 December 2010 00:16:01 GMT