Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

XSS is usually really, really bad anyway.

CSP plus trusted scripts...you should be working hard to prevent XSS.



Ideally, yes. In the current advertising market? No.


I don't know much about advertising.

Can't they be easily handled with an iframe?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: