Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
AgentME
6y ago
0 comments
Share
Those issues are only relevant to applications that display arbitrary HTML and already have XSS issues. Avoiding XSS is doable; with most web frameworks you're protected from XSS by default and have to specifically turn off the safeties to get XSS.
0 comments
default
newest
oldest
dependenttypes
6y ago
> Those issues are only relevant to applications that display arbitrary HTML and already have XSS issues
Such as signal!
https://ivan.barreraoro.com.ar/signal-desktop-html-tag-injec...
j
/
k
navigate · click thread line to collapse