← Back to Users
quasistoic's activity in the archive.
Ever heard of cross-site scripting? "ping" needs at the least to be implemented in such a fashion that only the originating site can get a ping.
Are you kidding me? The "ping" attribute is no more vulnerable to cross-site scripting than the "href" attribute itself.
Maybe we should just do away with hypertext to solve this dilemma. That's what it sounds like you're saying.