Skip to search.

Breaking News Visit Yahoo! News for the latest.

×Close this window

caplet · The Caplet Group

The Yahoo! Groups Product Blog

Check it out!

Group Information

  • Members: 72
  • Category: Security
  • Founded: May 11, 2007
  • Language: English
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Messages

Advanced
Messages Help
  Newest  |  < Newer  |  Older >  |  Oldest
Topics Messages Latest Post

JSLint.com contains an ADsafe feature. Its intent is to enforce a safe subset of JavaScript for use in ads and widgets. ADsafe requires no transformations. It...
36 Nov 11, 2010
6:46 pm

Douglas Crockford
douglascrock...
Send Email

ADSAFE.lib now subjects its name parameter to the same rules used generally on properties. Ankur Taly had discovered an attack by using a particular banned...
5 Oct 26, 2010
6:00 pm

Douglas Crockford
douglascrock...
Send Email

May crash your browser or page: http://es-lab.googlecode.com/svn/trunk/src/ses/index.html <http://es-lab.googlecode.com/svn/trunk/src/ses/index.html>Sources at...
3 Aug 31, 2010
3:57 pm

Ben Laurie
benlaurie2000
Send Email

I've been interested in ADsafe for a few months now as a potential way to allow 3rd parts apps to work within a safe sandbox. However, since ADsafe...
11 May 30, 2010
1:14 am

Mark S. Miller
erights@...
Send Email

A final reminder... W2SP 2010: Web 2.0 Security and Privacy 2010 Thursday, May 20 The Claremont Resort, Oakland, California Web site: http://w2spconf.com/2010 ...
1 May 11, 2010
9:27 pm

Larry Koved
larrykoved
Send Email

Call for Papers / Call for Participation: First workshop on Decentralized Coordination of Distributed Processes (DCDP 2010) http://soft.vub.ac.be/events/dcdp ...
1 Apr 13, 2010
12:44 am

Mark S. Miller
erights@...
Send Email

A quick reminder... This is announcement of the call for papers for the fourth in a series of successful workshops on topics related to security and privacy...
1 Mar 19, 2010
6:48 pm

Larry Koved
larrykoved
Send Email

This is announcement of the call for papers for the fourth in a series of successful workshops on topics related to security and privacy for Web 2.0. This...
2 Mar 5, 2010
6:25 pm

Larry Koved
larrykoved
Send Email

The first edition of adsafe.js is available at http://adsafe.org/adsafe.js. It still lacks dom wrappage and interwidget communication....
7 Aug 8, 2009
12:15 am

Douglas Crockford
douglascrock...
Send Email

We should add tests though to make sure we stay invulnerable to that. 2009/7/29 Mike Stay <metaweta@...> ... We should add tests though to make sure we...
1 Jul 31, 2009
1:39 pm

Mike Samuel
mikesamuel
Send Email

Hey I wanted to let you guys know that for now I'm discontinuing research on FBJS2. Basically at this time instead we're focusing on Facebook Connect (external...
1 Jul 16, 2009
3:31 am

marcel.laverdet
Send Email

Hi folks, Joel was playing around with ADsafe today and noticed that the verifier seems to be broken at the moment. For example, this widget passes the...
2 Jun 10, 2009
7:39 am

Douglas Crockford
douglascrock...
Send Email

I slimmed down the ADsafe banned list. These are the names of members that may not be accessed. This list is now: arguments callee caller constructor eval ...
5 May 25, 2009
11:24 pm

Tyler Close
tjclose
Send Email

... From: Mark S. Miller <erights@...> Date: Tue, May 19, 2009 at 7:52 PM Subject: Techtalk on EcmaScript 5 To: "es5-discuss@..."...
1 May 20, 2009
3:00 am

Mark S. Miller
erights@...
Send Email

This workshop may be of interest to subscribers of this mailing list Web 2.0 Security & Privacy 2009 Claremont Resort in Oakland, California May 21, 2009 ...
2 May 14, 2009
3:08 am

Larry Koved
larrykoved
Send Email

Doug, Do you know whether you will have time in the next few days (before March 25) to review a few of the papers submitted to W2SP this year? There are a few...
1 Mar 16, 2009
4:10 am

Larry Koved
larrykoved
Send Email

I added +tagName to the ADsafe query language. It selects the immediate sibling, so dom.q("h1+p") selects all of the <p> that immediately follow an <h1>....
1 Mar 6, 2009
6:32 pm

Douglas Crockford
douglascrock...
Send Email

This is announcement of the call for papers for the third in a series of successful workshops on topics related to security and privacy for Web 2.0. This...
1 Mar 2, 2009
8:26 pm

Larry Koved
larrykoved
Send Email

Suppose that S is a Unicode string in which each character matches ValidChar below, not containing the subsequences "<!", "</" or "]]>", and not containing...
7 Feb 18, 2009
9:54 pm

Mike Samuel
mikesamuel
Send Email

Consider the following JavaScript source: [ /[/]/ /foo]/ + bar According to the ES3 spec, this is interpreted as: [ new RegExp("[") ] / new RegExp("foo]") +...
13 Feb 11, 2009
3:10 am

Brendan Eich
brendaneich
Send Email

At http://wiki.ecmascript.org/doku.php?id=ses:ses_proposal_working_draft is posted a very rough first draft for a "Secure ECMAScript" standard, derived from...
3 Jan 25, 2009
6:55 am

Mark S. Miller
erights@...
Send Email

This is announcement of the call for papers for the third in a series of successful workshops on topics related to security and privacy for Web 2.0. This...
1 Jan 18, 2009
2:38 am

Larry Koved
larrykoved
Send Email

http://apps.yahoo.com/-yNmsEV4q/ I'm "ocap capo". It (and therefore Caja) also work on an iPhone. Thanks to the Yahoo! and Zynga folks! -- Cheers, --MarkM...
1 Jan 6, 2009
2:35 am

Mark S. Miller
erights@...
Send Email

The w3c Technical Architecture Group (TAG) discuss ocaps for the web starting at http://www.w3.org/2001/tag/2008/12/10-minutes#item03 teaser sample: 'DO: SW...
3 Jan 6, 2009
12:17 am

Tyler Close
tjclose
Send Email

The EcmaScript 3.1 draft standard is rapidly congealing towards an official standard. The Kona version at < ...
1 Nov 6, 2008
10:34 pm

Mark S. Miller
erights@...
Send Email

Live Labs has released a public preview of their Javascript sandbox. http://websandbox.livelabs.com/ See the clock sample: ...
1 Oct 25, 2008
12:41 am

marcel.laverdet
Send Email

I implemented PPK's focus hack (http://www.quirksmode.org/blog/archives/2008/04/delegating_the.html) in ADsafe, so focus and blur events may now be delegated....
1 Oct 23, 2008
6:02 pm

Douglas Crockford
douglascrock...
Send Email

There is another ADsafe demonstration widget at http://adsafe.org/sudoku.html...
6 Oct 9, 2008
3:15 pm

Alan Karp
alanhkarp
Send Email

ADsafe will block the bind method. The bind method proposed for ES3.1 is safe, but the bind methods provided by the current Ajax libraries are not because they...
13 Sep 8, 2008
8:06 pm

Douglas Crockford
douglascrock...
Send Email

ADsafe will now accept subscripting expressions that use the + prefix, so koda[bosonda] can be written as koda[+bosonda] instead of as ADSAFE.get(koda,...
1 Aug 31, 2008
12:39 am

Douglas Crockford
douglascrock...
Send Email
  Newest  |  < Newer  |  Older >  |  Oldest
Add to My Yahoo!      XML What's This?

Copyright © 2010 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines NEW - Help