Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1. Because you commonly are not.

2. Because it’s really easy to fuck up and leak attacker controlled content in markup, especially when the environment provides tons of tools to do things wrong and none to do things right. IME even when the environment provides tons of tools to do things right it’s an uphill battle (universe, idiots, yadda yadda).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: