| By RIA News Desk | Article Rating: |
|
| March 21, 2008 05:30 PM EDT | Reads: |
4,942 |
For over ten years attacks have been possible through the loopholes offered by the browser. A text that is benign in one content might be dangerous in another, third-party scripts can be embedded into URLs.

Web developers are blamed for this "But it's not their fault it's the system," says Crockford. What went wrong? JavaScript's Global Object is the root cause of Cross-Site Scripting (XSS) attacks, Crockford explains.
The Document Object Model (DOM) is the next problem. And the misuse of cookies as tokens of authority is a third.
"If the Web's been screwed up right from the beginning, why should we be worried about it now?" Crockford asks rhetorically.
One reasons is mashups, which Crockford calls "the most interesting innovation in software development for 20 years."
He then proposed a 3-prong strategy to fix the Web.
1. safe JavaScript subsets
2. small browser improvements
3. massive browser improvements
We need to replace JavaScript, Crockford insists.
Published March 21, 2008 Reads 4,942
Copyright © 2008 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By RIA News Desk
Ever since Google popularized a smarter, more responsive and interactive Web experience by using AJAX (Asynchronous JavaScript + XML) for its Google Maps & Gmail applications, SYS-CON's RIA News Desk has been covering every aspect of Rich Internet Applications and those creating and deploying them. If you have breaking RIA news, please send it to RIA@sys-con.com to share your product and company news coverage with AJAXWorld readers.
![]() |
Naysayer 03/19/08 07:27:59 AM EDT | |||
The Web survived 10 years...maybe we should just leve it alone? |
||||
- Oracle To Keynote Cloud Computing Expo
- Contrary Opinion: Why Silverlight is Good for Adobe
- Analytics for Adobe Air Applications
- Adobe’s Aiming ColdFusion at Multiple Clouds
- Eval JavaScript in a Global Context
- Fig Leaf Software to Exhibit at Government IT Conference & Expo
- Is Microsoft as Free as Open Source?
- Cloud Computing Journal: Adobe to Deliver ColdFusion in the Cloud
- The Planet Named “Bronze Sponsor” of Cloud Computing Expo
- Adobe Reader Sued
- AJAX World RIA Conference & Expo Kicks Off in New York City
- Adobe Enters Cloud Computing with LiveCycle
- Oracle To Keynote Cloud Computing Expo
- Social Media Terrorists
- Adobe Flash Media Server on iPhone
- Contrary Opinion: Why Silverlight is Good for Adobe
- Adobe Flash Based GetJar Surpasses a Half Billion Downloads
- Adobe ColdFusion 9 and ColdFusion Builder Public Betas Now Available
- Adobe Tries Commercializing Its Online Software
- Adobe Open Sources Flash Initiatives
- The Next Programming Models, RIAs and Composite Applications
- Where Are RIA Technologies Headed in 2008?
- Constructing an Application with Flash Forms from the Ground Up
- AJAX World RIA Conference & Expo Kicks Off in New York City
- CFEclipse: The Developer's IDE, Eclipse For ColdFusion
- Personal Branding Checklist
- Adobe Flex 2: Advanced DataGrid
- Has the Technology Bounceback Begun?
- Building a Zip Code Proximity Search with ColdFusion
- i-Technology Viewpoint: We Need Not More Frameworks, But Better Programmers



































