Skip to search.

Breaking News Visit Yahoo! News for the latest.

×Close this window

caplet · The Caplet Group

The Yahoo! Groups Product Blog

Check it out!

Group Information

  • Members: 72
  • Category: Security
  • Founded: May 11, 2007
  • Language: English
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Real people. Real stories. See how Yahoo! Groups impacts members worldwide.

Messages

Advanced
Messages Help
  Newest  |  < Newer  |  Older >  |  Oldest
Topics Messages Latest Post

Consider the following JavaScript source: [ /[/]/ /foo]/ + bar According to the ES3 spec, this is interpreted as: [ new RegExp("[") ] / new RegExp("foo]") +...
13 Feb 11, 2009
3:10 am

Brendan Eich
brendaneich
Send Email

At http://wiki.ecmascript.org/doku.php?id=ses:ses_proposal_working_draft is posted a very rough first draft for a "Secure ECMAScript" standard, derived from...
3 Jan 25, 2009
6:55 am

Mark S. Miller
erights@...
Send Email

This is announcement of the call for papers for the third in a series of successful workshops on topics related to security and privacy for Web 2.0. This...
1 Jan 18, 2009
2:38 am

Larry Koved
larrykoved
Send Email

http://apps.yahoo.com/-yNmsEV4q/ I'm "ocap capo". It (and therefore Caja) also work on an iPhone. Thanks to the Yahoo! and Zynga folks! -- Cheers, --MarkM...
1 Jan 6, 2009
2:35 am

Mark S. Miller
erights@...
Send Email

The w3c Technical Architecture Group (TAG) discuss ocaps for the web starting at http://www.w3.org/2001/tag/2008/12/10-minutes#item03 teaser sample: 'DO: SW...
3 Jan 6, 2009
12:17 am

Tyler Close
tjclose
Send Email

The EcmaScript 3.1 draft standard is rapidly congealing towards an official standard. The Kona version at < ...
1 Nov 6, 2008
10:34 pm

Mark S. Miller
erights@...
Send Email

Live Labs has released a public preview of their Javascript sandbox. http://websandbox.livelabs.com/ See the clock sample: ...
1 Oct 25, 2008
12:41 am

marcel.laverdet
Send Email

I implemented PPK's focus hack (http://www.quirksmode.org/blog/archives/2008/04/delegating_the.html) in ADsafe, so focus and blur events may now be delegated....
1 Oct 23, 2008
6:02 pm

Douglas Crockford
douglascrock...
Send Email

There is another ADsafe demonstration widget at http://adsafe.org/sudoku.html...
6 Oct 9, 2008
3:15 pm

Alan Karp
alanhkarp
Send Email

ADsafe will block the bind method. The bind method proposed for ES3.1 is safe, but the bind methods provided by the current Ajax libraries are not because they...
13 Sep 8, 2008
8:06 pm

Douglas Crockford
douglascrock...
Send Email

ADsafe will now accept subscripting expressions that use the + prefix, so koda[bosonda] can be written as koda[+bosonda] instead of as ADSAFE.get(koda,...
1 Aug 31, 2008
12:39 am

Douglas Crockford
douglascrock...
Send Email

Not directly object-capability news, but very good news from an ocap perspective. ... From: Brendan Eich <brendan@...> Date: Wed, Aug 13, 2008 at 2:26...
1 Aug 13, 2008
9:43 pm

Mark S. Miller
erights@...
Send Email

A sample ADsafe widget can be seen at http://www.adsafe.org/bats.html It plays the game of Bats....
1 Aug 12, 2008
2:04 pm

Douglas Crockford
douglascrock...
Send Email

On Fri, Jun 27, 2008 at 1:44 AM, Mario Heiderich ... Wow. No, we had no idea. I admit that I am shocked that the one tight encapsulation mechanism in...
3 Jun 27, 2008
9:09 pm

brendaneich
Send Email

I created a safe option in JSLint for checking the safe subset. The adsafe option assumes the safe option, and additionally checks for ADsafe widget...
1 Jun 21, 2008
11:33 pm

Douglas Crockford
douglascrock...
Send Email

I am developing an Ajax library for ADsafe. It applies a capability discipline to the dom tree, blocking access to parents and siblings. It wraps collections...
1 Jun 9, 2008
8:12 pm

Douglas Crockford
douglascrock...
Send Email

Recently I have been working on a new project, dojox.secure, to add a secure mechanism to Dojo for loading and executing untrusted code and widgets, and I...
1 Jun 9, 2008
6:34 pm

Kris Zyp
kriszyp
Send Email

I have been investigating an idea for a secure cross-site transport. It seems unlikely that no one has done anything like this before, but I can't find any...
1 Jun 9, 2008
5:32 pm

Kris Zyp
kriszyp
Send Email

http://ADsafe.org/ now describes three methods that provide the linkage between the guest code and the ADsafe runtime....
1 Jun 1, 2008
6:25 am

Douglas Crockford
douglascrock...
Send Email

I relaxed some of the restrictions on the get method. It still requires that the object is in fact an object (and not a function), but it allows the returning...
1 May 24, 2008
9:45 pm

Douglas Crockford
douglascrock...
Send Email

ADsafe now allows long dot expressions that refine the allowed global variables. So ADSAFE.koda.bosanda.bosoya.tikki.ottobo(); is now acceptable. JSLint's UI...
1 May 23, 2008
2:53 am

Douglas Crockford
douglascrock...
Send Email

... From: Douglas Crockford <douglas@...> To: David-Sarah Hopwood <david.hopwood@...>, Mark Miller <erights@...> ...
11 May 22, 2008
12:17 am

David-Sarah Hopwood
david.hopwood@...
Send Email

... To: Douglas Crockford <douglas@...> Subject: ADsafe attack From: David-Sarah Hopwood <david.hopwood@...> (function () { ...
1 May 21, 2008
2:47 am

David-Sarah Hopwood
david.hopwood@...
Send Email

I am on the program committee of the second workshop on Web 2.0 Security and Privacy (http://seclab.cs.rice.edu/w2sp/2008/cfp.html). It will be held the day...
3 May 5, 2008
2:12 am

Larry Koved
larrykoved
Send Email

ADsafe does not allow access to Date or to Math.random(). This is because we want to be able to sample ads to test their behavior and contractual compliance....
1 May 4, 2008
4:02 pm

Douglas Crockford
douglascrock...
Send Email

I added arguments to the set of excluded members. The set now contains apply arguments call callee caller constructor eval prototype unwatch valueOf watch...
1 Apr 15, 2008
4:25 pm

Douglas Crockford
douglascrock...
Send Email

I am relaxing ADsafe to allow access to these standard globals: Array Boolean Date decodeURI decodeURIComponent encodeURI encodeURIComponent Error escape...
15 Apr 16, 2008
2:00 am

Douglas Crockford
douglascrock...
Send Email

Is there any documentation available on the specific attacks that the various rules in ADsafe are protecting against? Most of the rules are pretty obvious, but...
13 Apr 8, 2008
4:43 pm

Douglas Crockford
douglascrock...
Send Email

Doug/ADsafe people, Has there been any efforts to produce a lightweight minimal-sized ADsafe validator? With the coming browser capabilities in Cross-site XHR...
16 Mar 22, 2008
3:35 am

Kris Zyp
kriszyp
Send Email

I have been thinking about capabilities-based security and ES subsets like ADsafe and Caja, and was thinking about another subset that is intriguing to me and...
1 Feb 27, 2008
9:02 pm

Kris Zyp
kriszyp
Send Email
  Newest  |  < Newer  |  Older >  |  Oldest
Add to My Yahoo!      XML What's This?

Copyright © 2010 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines NEW - Help