Trusting Anil Dash not to f*ck up my site with evil JavaScript
Below is a snippet of an entry from Anil Dash‘s blog on the possibilities of using embed, object and JavaScript for serving all kinds of content — not just movies.
The obvious question is ‘How much should you trust code from strangers?’ And can this be done in a safe(-ish), secure(-ish) way?
Possibly related: Cross-domain Ajax links and Access Control for Cross-site Requests (implemented in Firefox 3)