Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the point was that it's inherently less safe to allow arbitrary markup and then attempt to sanitize it, than to make a full parser that's incapable of generating unsafe HTML at any stage, all other things being equal.

The safety of widely-deployed Markdown + sanitizer libraries is largely thanks to testing at scale and a history of patches for XSS vulnerabilities.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: