Reply to post:

Gotta have standards? Security boffins not API about bloated browsers

Ottman001

These features are useful to someone but having them available to any script on a page is obviously increasing the attack area available.

There should be some way to turn on APIs that can't be done in code. For instance, add tags within the head of a HTML document that first switch off all APIs (we always have to think of backwards compatibility) and then list the APIs required by the page.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon