Path: csiph.com!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!newsreader4.netcologne.de!news.netcologne.de!newsfeed.arcor.de!newsspool2.arcor-online.net!news.arcor.de.POSTED!not-for-mail Content-Type: text/plain; charset="UTF-8" Message-ID: <2144906.mcRnARlMXY@PointedEars.de> From: Thomas 'PointedEars' Lahn Reply-To: Thomas 'PointedEars' Lahn Organization: PointedEars Software (PES) Date: Sun, 11 Nov 2012 20:41:05 +0100 User-Agent: KNode/4.4.11 Content-Transfer-Encoding: 8Bit X-Face: %i>XG-yXR'\"2P/C_aO%~;2o~?g0pPKmbOw^=NT`tprDEf++D.m7"}HW6.#=U:?2GGctkL,f89@H46O$ASoW&?s}.k+&. <2261899.gBobAo4G4S@PointedEars.de> <4265d7df-81e2-4c58-a16d-cafc435a1e88@j19g2000vba.googlegroups.com> <28208070.qZZrvzLHK0@PointedEars.de> <21f7f06f-0b19-46da-ae77-29c269196491@o30g2000vbu.googlegroups.com> Followup-To: comp.lang.javascript MIME-Version: 1.0 Lines: 34 NNTP-Posting-Date: 11 Nov 2012 20:41:06 CET NNTP-Posting-Host: 2786e8da.newsspool1.arcor-online.net X-Trace: DXC=^mbF@RLA\[^mG86`U=_nC_ic==]BZ:af^4Fo<]lROoRQnkgeX?EC@@PBeLlkVT3cfTDZm8W4\YJN\J`:FmdeL>KPiU3I74H>BYP6:h1kBPI84V X-Complaints-To: usenet-abuse@arcor.de Xref: csiph.com comp.lang.javascript:17176 Asen Bozhilov wrote: > Thomas 'PointedEars' Lahn wrote: >> Even if it was not a cross-origin request, there is no guarantee that the >> data are coming from the requested site. You can work around the SOP >> yourself by setting up a transparent proxy for certain requests to your >> server, and there can still be a man-in-the-middle (MITM)-attack when you >> did not. > > Man in the middle is not the case. Usually serious API-s communicate > through the SSL, which breaks MITM attacks. It certainly helps to avoid them; it does not prevent them, and it certainly does not "break" them in any meaning of the word. There is a good reason why Microsoft recommended upgrading to 1024-bit certificates recently. > If the communication between the your client and your server is not > secured and if there is MITM, your client has definetely more troubles > to care about JSON parsing. While I was not talking about JSON specifically, your logic is still flawed. > If the resource is *trusted* still don't see the problem with Function > constructr. Trust is relative. There is no 100% secure system. PointedEars -- > If you get a bunch of authors […] that state the same "best practices" > in any programming language, then you can bet who is wrong or right... Not with javascript. Nonsense propagates like wildfire in this field. -- Richard Cornford, comp.lang.javascript, 2011-11-14