| By RIA News Desk | Article Rating: |
|
| March 21, 2008 05:30 PM EDT | Reads: |
4,807 |
For over ten years attacks have been possible through the loopholes offered by the browser. A text that is benign in one content might be dangerous in another, third-party scripts can be embedded into URLs.

Web developers are blamed for this "But it's not their fault it's the system," says Crockford. What went wrong? JavaScript's Global Object is the root cause of Cross-Site Scripting (XSS) attacks, Crockford explains.
The Document Object Model (DOM) is the next problem. And the misuse of cookies as tokens of authority is a third.
"If the Web's been screwed up right from the beginning, why should we be worried about it now?" Crockford asks rhetorically.
One reasons is mashups, which Crockford calls "the most interesting innovation in software development for 20 years."
He then proposed a 3-prong strategy to fix the Web.
1. safe JavaScript subsets
2. small browser improvements
3. massive browser improvements
We need to replace JavaScript, Crockford insists.
Published March 21, 2008 Reads 4,807
Copyright © 2008 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
About RIA News Desk
Ever since Google popularized a smarter, more responsive and interactive Web experience by using AJAX (Asynchronous JavaScript + XML) for its Google Maps & Gmail applications, SYS-CON's RIA News Desk has been covering every aspect of Rich Internet Applications and those creating and deploying them. If you have breaking RIA news, please send it to RIA@sys-con.com to share your product and company news coverage with AJAXWorld readers.
![]() |
Naysayer 03/19/08 07:27:59 AM EDT | |||
The Web survived 10 years...maybe we should just leve it alone? |
||||
- AJAX World RIA Conference & Expo Kicks Off in New York City
- Ulitzer’s Amazing First 30 Days in Public Beta
- "Government IT Expo" to Highlight Cloud Computing and SOA
- Will Ulitzer Dominate News Content on The Web? -Gartner
- Clear Toolkit 4: The Road Map
- Creating Adobe AIR Native Menu with Flash CS4
- Ulitzer Responds to Published Reports
- Ulitzer vs. Ning - a Quick Review
- Adobe AIR: Creating Dock and System Tray Icon Menus
- Social Media Terrorists
- AJAX World RIA Conference & Expo Kicks Off in New York City
- Web Services Using ColdFusion and Apache CXF
- Adobe Takes LiveCycle into the Cloud
- Ulitzer’s Amazing First 30 Days in Public Beta
- Adobe Creates a Sandbox in the Sky
- "Government IT Expo" to Highlight Cloud Computing and SOA
- Will Ulitzer Dominate News Content on The Web? -Gartner
- The Role of an RIA in the Enterprise
- Clear Toolkit 4: The Road Map
- Creating Adobe AIR Native Menu with Flash CS4
- The Next Programming Models, RIAs and Composite Applications
- Constructing an Application with Flash Forms from the Ground Up
- AJAX World RIA Conference & Expo Kicks Off in New York City
- CFEclipse: The Developer's IDE, Eclipse For ColdFusion
- Personal Branding Checklist
- Adobe Flex 2: Advanced DataGrid
- i-Technology Viewpoint: We Need Not More Frameworks, But Better Programmers
- The Asynchronous CFML Gateway
- Building a Zip Code Proximity Search with ColdFusion
- Web Services Using ColdFusion and Apache CXF






































