[p2pu-dev] Google's Dart

Dan Diebolt dandiebolt at gmail.com
Tue Oct 11 20:11:35 UTC 2011


Do you realize that you currently *CAN* embed a <iframe>s using the
embed.lyembed code? It is broken only in the sense that it doesn't
display properly
- the attack surface is no larger or smaller because the visual display of
the <iframe> is broken. So whatever attack surface you imagine the <iframe>
to have, you aren't disallow any <iframe>'s.

So in a nutshell what I am hearing is this: we don't want to fix the current
embed.ly display problem because we think <iframe>'s are naughty but we are
just going to ignore the issue and allow users to embed <iframe>'s via
embed.ly. That doesn't make any sense.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.p2pu.org/pipermail/p2pu-dev/attachments/20111011/4192325a/attachment.html>


More information about the p2pu-dev mailing list