[whatwg] Security attacks on local storage

2009-02-20 Thread David Gerard
http://research.zscaler.com/2009/02/practical-example-of-cssqli-using.html http://it.slashdot.org/article.pl?sid=09/02/19/2055210 - d.

Re: [whatwg] Security attacks on local storage

2009-02-20 Thread Anne van Kesteren
On Fri, 20 Feb 2009 12:36:32 +0100, David Gerard dger...@gmail.com wrote: http://research.zscaler.com/2009/02/practical-example-of-cssqli-using.html http://it.slashdot.org/article.pl?sid=09/02/19/2055210 The subject line is rather misleading. It should be pretty clear that if a website is

Re: [whatwg] Security attacks on local storage

2009-02-20 Thread Ian Hickson
On Fri, 20 Feb 2009, David Gerard wrote: http://research.zscaler.com/2009/02/practical-example-of-cssqli-using.html http://it.slashdot.org/article.pl?sid=09/02/19/2055210 As Anne noted, this appears to be a bogus claim. I do not intend to change the spec here. If anyone sees an actual