<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Making JavaScript Safe with Google Caja</title>
	<atom:link href="http://ajaxian.com/archives/making-javascript-safe-with-google-caja/feed" rel="self" type="application/rss+xml" />
	<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja</link>
	<description>Cleaning up the web with Ajax</description>
	<lastBuildDate>Thu, 09 Feb 2012 06:55:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2</generator>
	<item>
		<title>By: maddesa</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-275728</link>
		<dc:creator>maddesa</dc:creator>
		<pubDate>Wed, 30 Sep 2009 18:04:18 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-275728</guid>
		<description>@Aphrodisiac yes google is behind this.  There was a great presentation on this at The Ajax Experience in Boston two weeks ago.

@misuba not to speak for the project, Caja basically reads in a third party script, and rewrites it in a safe way.  it allows you to compose application from untrusted third parties and even enables communication between those scripts.

@Jim I think you have to remember that users of this site don&#039;t accurately represent everyday users.  I know this may sound crazy, but most people barely know what a browser is, never mind putting thought into which one is better, faster, safer.  Most people just know that the Big Blue E that &quot;came with&quot; their computer is the internet.</description>
		<content:encoded><![CDATA[<p>@Aphrodisiac yes google is behind this.  There was a great presentation on this at The Ajax Experience in Boston two weeks ago.</p>
<p>@misuba not to speak for the project, Caja basically reads in a third party script, and rewrites it in a safe way.  it allows you to compose application from untrusted third parties and even enables communication between those scripts.</p>
<p>@Jim I think you have to remember that users of this site don&#8217;t accurately represent everyday users.  I know this may sound crazy, but most people barely know what a browser is, never mind putting thought into which one is better, faster, safer.  Most people just know that the Big Blue E that &#8220;came with&#8221; their computer is the internet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aphrodisiac</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-266275</link>
		<dc:creator>Aphrodisiac</dc:creator>
		<pubDate>Thu, 31 Jul 2008 10:26:26 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-266275</guid>
		<description>is google behind this?</description>
		<content:encoded><![CDATA[<p>is google behind this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: misuba</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257175</link>
		<dc:creator>misuba</dc:creator>
		<pubDate>Mon, 15 Oct 2007 16:10:11 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257175</guid>
		<description>This is all great, but... what IS Caja exactly?</description>
		<content:encoded><![CDATA[<p>This is all great, but&#8230; what IS Caja exactly?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas Hansen</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257140</link>
		<dc:creator>Thomas Hansen</dc:creator>
		<pubDate>Sun, 14 Oct 2007 00:01:40 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257140</guid>
		<description>I think it&#039;s really sad that such a great developer as Douglas is determined on &quot;fixing something that&#039;s NOT broken&quot;... :(
BTW security in Ajax is a NON-issue if you&#039;re using a server-centric Ajax Framework like e.g. Gaia Ajax Widgets...
If I were to &quot;break&quot; the language and don&#039;t think about backwards compatibility I&#039;d say it&#039;s a 100 times more important to bring in namespaces and avoid the &quot;garbage bin&quot; of &quot;window.x&quot; - global &quot;namespace&quot;...</description>
		<content:encoded><![CDATA[<p>I think it&#8217;s really sad that such a great developer as Douglas is determined on &#8220;fixing something that&#8217;s NOT broken&#8221;&#8230; :(<br />
BTW security in Ajax is a NON-issue if you&#8217;re using a server-centric Ajax Framework like e.g. Gaia Ajax Widgets&#8230;<br />
If I were to &#8220;break&#8221; the language and don&#8217;t think about backwards compatibility I&#8217;d say it&#8217;s a 100 times more important to bring in namespaces and avoid the &#8220;garbage bin&#8221; of &#8220;window.x&#8221; &#8211; global &#8220;namespace&#8221;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christian Pulcinelli</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257131</link>
		<dc:creator>Christian Pulcinelli</dc:creator>
		<pubDate>Sat, 13 Oct 2007 17:33:04 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257131</guid>
		<description>Javascript is a strong way to make a site look more &quot;cool&quot; or easy to use but all the people i know think twice before using javascript to manage data, they prefer many other languages but all of them would be happy to manage all from one language, otherwise using one for a feauture and one for another... why the &quot;bosses&quot; don&#039;t work on this?</description>
		<content:encoded><![CDATA[<p>Javascript is a strong way to make a site look more &#8220;cool&#8221; or easy to use but all the people i know think twice before using javascript to manage data, they prefer many other languages but all of them would be happy to manage all from one language, otherwise using one for a feauture and one for another&#8230; why the &#8220;bosses&#8221; don&#8217;t work on this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vytas</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257116</link>
		<dc:creator>Vytas</dc:creator>
		<pubDate>Sat, 13 Oct 2007 07:21:54 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257116</guid>
		<description>Post advertisement at http://fivq.com/ . There you can offer your services, find gigs (short term jobs) or long term jobs. It is good place who would like to work remotely. Also there you can promote your website, your services. Between its absolutely free to post and no registration needed.</description>
		<content:encoded><![CDATA[<p>Post advertisement at <a href="http://fivq.com/" rel="nofollow">http://fivq.com/</a> . There you can offer your services, find gigs (short term jobs) or long term jobs. It is good place who would like to work remotely. Also there you can promote your website, your services. Between its absolutely free to post and no registration needed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257108</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Sat, 13 Oct 2007 00:21:07 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257108</guid>
		<description>Seems to me that everyday users need to be able to clearly see what information is being sent from their browser and to what destination--along with a control for permitting it and denying it. This way individuals remain responsible for their own information, privacy, etc and are empowered to control it (along with firewall, adblockers, etc). Personally I see this as having way more longevity, reliability and simplicity than fixing/changing the languages/technologies across all the browsers, getting everyone to use the new products, educating developers, etc, etc.</description>
		<content:encoded><![CDATA[<p>Seems to me that everyday users need to be able to clearly see what information is being sent from their browser and to what destination&#8211;along with a control for permitting it and denying it. This way individuals remain responsible for their own information, privacy, etc and are empowered to control it (along with firewall, adblockers, etc). Personally I see this as having way more longevity, reliability and simplicity than fixing/changing the languages/technologies across all the browsers, getting everyone to use the new products, educating developers, etc, etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chess</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257097</link>
		<dc:creator>Chess</dc:creator>
		<pubDate>Fri, 12 Oct 2007 20:21:33 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257097</guid>
		<description>I agree, ripping off the entire content of someone&#039;s article isn&#039;t satisfied by a courtesy link to it. Bad move</description>
		<content:encoded><![CDATA[<p>I agree, ripping off the entire content of someone&#8217;s article isn&#8217;t satisfied by a courtesy link to it. Bad move</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Meyer</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257088</link>
		<dc:creator>Justin Meyer</dc:creator>
		<pubDate>Fri, 12 Oct 2007 18:42:12 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257088</guid>
		<description>This would make it much easier for mashups to run untrusted scripts, but I think this really needs to happen in the browser.  

Of course, due to all the browser inconsistencies of the 90&#039;s, I can understand why people are afraid of that.  But there is no substitute for correctness.

Hopefully, the big boys of the internet (Google / Yahoo) are putting pressure on the browser vendors to make these changes.  But, what&#039;s the motivation (ie $$) to improve browsers anymore?</description>
		<content:encoded><![CDATA[<p>This would make it much easier for mashups to run untrusted scripts, but I think this really needs to happen in the browser.  </p>
<p>Of course, due to all the browser inconsistencies of the 90&#8242;s, I can understand why people are afraid of that.  But there is no substitute for correctness.</p>
<p>Hopefully, the big boys of the internet (Google / Yahoo) are putting pressure on the browser vendors to make these changes.  But, what&#8217;s the motivation (ie $$) to improve browsers anymore?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Holton</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257087</link>
		<dc:creator>Mark Holton</dc:creator>
		<pubDate>Fri, 12 Oct 2007 18:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257087</guid>
		<description>...I love Dion&#039;s &#039;teaser&#039; quote... it&#039;s the entire Crockford article copied and pasted ;)
Great info though, as always!  Thanks, guys.</description>
		<content:encoded><![CDATA[<p>&#8230;I love Dion&#8217;s &#8216;teaser&#8217; quote&#8230; it&#8217;s the entire Crockford article copied and pasted ;)<br />
Great info though, as always!  Thanks, guys.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan Bond-Caron</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257079</link>
		<dc:creator>Jonathan Bond-Caron</dc:creator>
		<pubDate>Fri, 12 Oct 2007 17:18:13 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257079</guid>
		<description>Looks official (// Copyright (C) 2007 Google Inc.), research focused

Doing this in javascript doesn&#039;t make any practical sense to me, but their research is amazing: 
http://google-caja.googlecode.com/files/caja-spec-2007-10-11.pdf

We need to fix the browser that for sure. Would be nice to see collaboration, there&#039;s a new effort at OpenAjax to propose changes to browser vendors:

http://www.openajax.org/member/wiki/Runtime</description>
		<content:encoded><![CDATA[<p>Looks official (// Copyright (C) 2007 Google Inc.), research focused</p>
<p>Doing this in javascript doesn&#8217;t make any practical sense to me, but their research is amazing:<br />
<a href="http://google-caja.googlecode.com/files/caja-spec-2007-10-11.pdf" rel="nofollow">http://google-caja.googlecode.com/files/caja-spec-2007-10-11.pdf</a></p>
<p>We need to fix the browser that for sure. Would be nice to see collaboration, there&#8217;s a new effort at OpenAjax to propose changes to browser vendors:</p>
<p><a href="http://www.openajax.org/member/wiki/Runtime" rel="nofollow">http://www.openajax.org/member/wiki/Runtime</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uriel Katz</title>
		<link>http://ajaxian.com/archives/making-javascript-safe-with-google-caja/comment-page-1#comment-257076</link>
		<dc:creator>Uriel Katz</dc:creator>
		<pubDate>Fri, 12 Oct 2007 16:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/archives/making-javascript-safe-with-google-caja#comment-257076</guid>
		<description>is it a official google project?</description>
		<content:encoded><![CDATA[<p>is it a official google project?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

