Hacker News
new
past
comments
ask
show
jobs
points
by
dividuum
5 hours ago
|
comments
by
WatchDog
5 hours ago
|
[-]
If it were vulnerable to XSS, why would you even want it properly signed by a CA? People almost never inspect the certificates of working websites, the only time they might look at it is when it fails validation.
reply