<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Video and audio tags and cross origin access</title>
	<atom:link href="http://ajaxian.com/archives/video-audio-cross-origin/feed" rel="self" type="application/rss+xml" />
	<link>http://ajaxian.com/archives/video-audio-cross-origin</link>
	<description>Cleaning up the web with Ajax</description>
	<lastBuildDate>Thu, 17 May 2012 07:43:39 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: jayridge</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268915</link>
		<dc:creator>jayridge</dc:creator>
		<pubDate>Mon, 10 Nov 2008 23:57:26 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268915</guid>
		<description>security kills invention. i will accept the risk.</description>
		<content:encoded><![CDATA[<p>security kills invention. i will accept the risk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AdrenalinMd</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268914</link>
		<dc:creator>AdrenalinMd</dc:creator>
		<pubDate>Mon, 10 Nov 2008 23:35:18 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268914</guid>
		<description>That makes HTML5 useless. Flash doesn&#039;t have such a limitation.</description>
		<content:encoded><![CDATA[<p>That makes HTML5 useless. Flash doesn&#8217;t have such a limitation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kit</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268913</link>
		<dc:creator>Kit</dc:creator>
		<pubDate>Mon, 10 Nov 2008 23:33:48 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268913</guid>
		<description>I think the big failure here is that Chris is pointing out the very failure in blocking XS functionality because it&#039;s a never-ending spiral of tags that can be exploited. In order to maintain compatibility with existing sites, though, as Chris mentions, browsers must permit cross-site access to CSS and images.

Video tags won&#039;t ever supplant existing formats (such as FLV) if there&#039;s no way to cross-embed it. Think YouTube.

The better solution is something specific to do with the media itself; some way to explicitly permit embedding. Even if it&#039;s just using the REFERER header at the server end to restrict serving of the file to requesters of the expected domains.

This is a security issue that should be handled by the media servers, not the web browsers.</description>
		<content:encoded><![CDATA[<p>I think the big failure here is that Chris is pointing out the very failure in blocking XS functionality because it&#8217;s a never-ending spiral of tags that can be exploited. In order to maintain compatibility with existing sites, though, as Chris mentions, browsers must permit cross-site access to CSS and images.</p>
<p>Video tags won&#8217;t ever supplant existing formats (such as FLV) if there&#8217;s no way to cross-embed it. Think YouTube.</p>
<p>The better solution is something specific to do with the media itself; some way to explicitly permit embedding. Even if it&#8217;s just using the REFERER header at the server end to restrict serving of the file to requesters of the expected domains.</p>
<p>This is a security issue that should be handled by the media servers, not the web browsers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: doublec</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268912</link>
		<dc:creator>doublec</dc:creator>
		<pubDate>Mon, 10 Nov 2008 23:05:23 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268912</guid>
		<description>AndiSkater, Chris Double is very aware that Firefox and others are open source and can be modified. In fact, Chris Double is not a fan of the access restrictions, even though he blogged about it. It&#039;s my opinion it&#039;ll be a big barrier to adoption of video and audio. 

On the other hand I respect jonas and he has given this a lot of thought and I see his points. I don&#039;t know of a good solution.</description>
		<content:encoded><![CDATA[<p>AndiSkater, Chris Double is very aware that Firefox and others are open source and can be modified. In fact, Chris Double is not a fan of the access restrictions, even though he blogged about it. It&#8217;s my opinion it&#8217;ll be a big barrier to adoption of video and audio. </p>
<p>On the other hand I respect jonas and he has given this a lot of thought and I see his points. I don&#8217;t know of a good solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mblaney</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268909</link>
		<dc:creator>mblaney</dc:creator>
		<pubDate>Mon, 10 Nov 2008 22:03:57 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268909</guid>
		<description>In other news, the &#039;anchor&#039; tag will also be modified to prevent cross site access. It is currently possible for an attacker to set up a link that redirects the user to &#039;attacker.com&#039; which could be harmful. In future only internal links will be possible.</description>
		<content:encoded><![CDATA[<p>In other news, the &#8216;anchor&#8217; tag will also be modified to prevent cross site access. It is currently possible for an attacker to set up a link that redirects the user to &#8216;attacker.com&#8217; which could be harmful. In future only internal links will be possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: whoisyeco</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268889</link>
		<dc:creator>whoisyeco</dc:creator>
		<pubDate>Mon, 10 Nov 2008 15:58:29 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268889</guid>
		<description>Restrictions on video?, the streaming methods and media servers gives solutions enought for this issue... 

I agree that some of the videos requires some security but those are only very specific cases.

I don&#039;t think this has to be a front-end issue.</description>
		<content:encoded><![CDATA[<p>Restrictions on video?, the streaming methods and media servers gives solutions enought for this issue&#8230; </p>
<p>I agree that some of the videos requires some security but those are only very specific cases.</p>
<p>I don&#8217;t think this has to be a front-end issue.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AndiSkater</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268878</link>
		<dc:creator>AndiSkater</dc:creator>
		<pubDate>Mon, 10 Nov 2008 13:32:11 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268878</guid>
		<description>Restrictions, restrictions, restrictions. That&#039;s what we need, restrictions. It seems everything is about restrictions and security it should enforce, today. I don&#039;t understand why we need this. So the audio and video tags have to be restricted, because else someone could access a video on a non official web site? Has Chris Double ever thought about the fact, that Firefox or Webkit are open source and every person with some programmings skills could compile a version without these restrictions?
Probably the world would be much more secure, if everyone lived in a cage and would never go out. Every time I go shopping, I risk to be pickpocketed. Everytime I drive my car, I risk to have a crash. Should be really give up our freedom for more and more security?

I don&#039;t think so.</description>
		<content:encoded><![CDATA[<p>Restrictions, restrictions, restrictions. That&#8217;s what we need, restrictions. It seems everything is about restrictions and security it should enforce, today. I don&#8217;t understand why we need this. So the audio and video tags have to be restricted, because else someone could access a video on a non official web site? Has Chris Double ever thought about the fact, that Firefox or Webkit are open source and every person with some programmings skills could compile a version without these restrictions?<br />
Probably the world would be much more secure, if everyone lived in a cage and would never go out. Every time I go shopping, I risk to be pickpocketed. Everytime I drive my car, I risk to have a crash. Should be really give up our freedom for more and more security?</p>
<p>I don&#8217;t think so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: igitur</title>
		<link>http://ajaxian.com/archives/video-audio-cross-origin/comment-page-1#comment-268877</link>
		<dc:creator>igitur</dc:creator>
		<pubDate>Mon, 10 Nov 2008 12:54:18 +0000</pubDate>
		<guid isPermaLink="false">http://ajaxian.com/?p=5010#comment-268877</guid>
		<description>Sorry, I don&#039;t remember why PHP did so well. Would like to have my memory refreshed though...</description>
		<content:encoded><![CDATA[<p>Sorry, I don&#8217;t remember why PHP did so well. Would like to have my memory refreshed though&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

