2015 Apr 12, 10:39 2015 Apr 12, 10:27 2015 Apr 11, 11:12 2015 Apr 11, 10:58 2015 Apr 11, 10:19
Naming is important: in Rails you can output raw unescaped HTML with
.safe_html - in React a similar API is called dangerouslySetInnerHTML
2015 Apr 10, 11:21 2015 Apr 9, 9:30 2015 Apr 9, 4:34 2015 Apr 6, 9:21
How to decide to trust a password mgr? Have to write my own to be sure of author's
intentions. But then also sure mgr will have dumb flaws.
2015 Apr 3, 7:24
Go watch Primer. Do it. It's the only movie you'll still feel like an idiot watching
after 5 times. Seriously. It's amazing.
2015 Apr 2, 10:43 2015 Mar 30, 10:52
Or from GitHub's POV, how else can you use this XSS? Example: Open a new window with
info on howto subvert particular censorship. What else?
2015 Mar 30, 12:31 2015 Mar 29, 11:10 2015 Mar 29, 11:01
Faust: I want to XSS everyone! Devil: Sign here… Faust: Oh no, GitHub server's can't
handle the traffic! ♪ Twilight zone theme ♪
2015 Mar 29, 10:53 2015 Mar 26, 2:45 2015 Mar 26, 2:40
@waxpancake Just make Waxy automagically
switch over if you don’t post anything manually for N days.
2015 Mar 25, 12:15