Subverting AJAX
This paper, Subverting AJAX (pdf as html via Google), was presented at the Chaos Communication Congress and has been getting quite a bit of press. I'm not going to add anything of interest because I'm not a Web Application Security Expert.. but I wanted to share the reading associated with the article...
Interesting Post #1 -- Matasano Chargen -- Thomas Ptacek comments on how, while the paper is a fun read, there's nothing overly new presented.
Interesting Post #2 -- Jeremiah Grossman -- A completely opposite side of the spectrum, calling the research cutting edge, yet implying that some of it is impossible/impractical.
As I said, I can't say one way or another, but it was definitely interesting to read... I gather I need to put a little more time into AJAX in order to make up my own opinion of the paper.
Peace,
HT
