Profile

User's avatar
npub1j2l6...tszt
npub1j2l6...tszt
Today we published two blog posts about an HTML specification change that makes mutation XSS harder to exploit! Long story short: `<` and `>` are now escaped in attributes. * Blog post about security rationale behind this change: * Blog post about how it affects web developers: