-
Argh. Sucks to be in this position; my condolences to the affected staff members.
-
Beck starts a new project – cover an album in a day, with an assortment of guest artists. This time the project is The Velvet Underground and Nico. Sounds good so far. Interesting viral marketing campaign too: when @beck follows you on Twitter you pay attention.
-
The Content Security Policy proposal suggests a series of x-headers that specify allowed content domains. As the introduction points out, it needs to be implemented together with cross-site request forgery (CSRF) protection, or an attacker could inject script via XSS AND whitelist it via CSRF.
-
Mozilla prepares to implement domain whitelisting for JavaScript. Remains to be seen whether it will be more or less effective than simply fixing XSS bugs.
-
How MobileMe just got a killer feature: Find My iPhone helps track down a thief.
-
I keep forgetting to bookmark this: Using simple CSS to make attractive buttons out of clean markup.