[theora] <video/> and cross site scripting policy.

Ralph Giles giles at xiph.org
Thu Nov 6 17:29:11 PST 2008


On Thu, Nov 6, 2008 at 4:40 PM, Robert O'Callahan <robert at ocallahan.org> wrote:

> If you can't make sense of the points I raised in my last email (or you
> think I made them in bad faith), then I guess we can't communicate.

I'm sorry if I expressed myself badly. I've certainly never known you
to act in bad faith!

Trying again: this discussion, to the extent that many of us here are
objecting to the cross-site controls as you've described them, is
about the tradeoff between security and ease of use. I think you've
weighed security too heavily, and am trying to understand why our
conclusions are different.

I can agree there's little difference in the barrier between people
with their own little server and large organizations who have already
thought about all this. The burden falls mainline on mid-size sites.
The amateurs and startups, if you will.

 -r


More information about the theora mailing list