<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DamnIT Remote Javscript Error Reporting</title>
	<atom:link href="http://www.ajaxbestiary.com/2008/03/23/damnit-remote-javscript-error-reporting/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ajaxbestiary.com/2008/03/23/damnit-remote-javscript-error-reporting/</link>
	<description>AJAX Development, News, Techniques &#38; More</description>
	<lastBuildDate>Tue, 24 Jan 2012 01:39:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Justin Meyer</title>
		<link>http://www.ajaxbestiary.com/2008/03/23/damnit-remote-javscript-error-reporting/comment-page-1/#comment-1113</link>
		<dc:creator>Justin Meyer</dc:creator>
		<pubDate>Mon, 24 Mar 2008 02:48:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.ajaxbestiary.com/2008/03/23/damnit-remote-javscript-error-reporting/#comment-1113</guid>
		<description>Don, thanks for the post!  Just to clarify a few points on your post ...

The system isn&#039;t email only.  It records the errors to our system.  DamnIT provides limited project management functionality.  You can mark errors as accepted, in progress, or closed.  It will also show you your most common errors.

Sensitive information is an important issue.  Although the information being sent to us is safe (sent via https).  You basically hand us the keys to your website as we can execute JavaScript on your website and do anything the user can do.

DamnIT and any other remotely loaded JavaScript (google analytics) shouldn&#039;t be used unless trust the vendor completely. 

Another security issue is that your html content is saved on our machines.  If we were evil (we aren&#039;t) we could read it.  However, it&#039;s save from everyone else.

You&#039;re correct about our future plans with DamnIT.  In the very short term, we are going to building something like SubSpace (http://www2007.org/program/paper.php?id=801) to prevent cross site scripting attacks.  We will also provide an option not to save the HTML content on our server.

Eventually, there will be a non-central version of DamnIT that people can download and install on their own.  This will avoid all the security issues and perform better because it won&#039;t have to be cross domain.</description>
		<content:encoded><![CDATA[<p>Don, thanks for the post!  Just to clarify a few points on your post &#8230;</p>
<p>The system isn&#8217;t email only.  It records the errors to our system.  DamnIT provides limited project management functionality.  You can mark errors as accepted, in progress, or closed.  It will also show you your most common errors.</p>
<p>Sensitive information is an important issue.  Although the information being sent to us is safe (sent via https).  You basically hand us the keys to your website as we can execute JavaScript on your website and do anything the user can do.</p>
<p>DamnIT and any other remotely loaded JavaScript (google analytics) shouldn&#8217;t be used unless trust the vendor completely. </p>
<p>Another security issue is that your html content is saved on our machines.  If we were evil (we aren&#8217;t) we could read it.  However, it&#8217;s save from everyone else.</p>
<p>You&#8217;re correct about our future plans with DamnIT.  In the very short term, we are going to building something like SubSpace (<a href="http://www2007.org/program/paper.php?id=801" rel="nofollow">http://www2007.org/program/paper.php?id=801</a>) to prevent cross site scripting attacks.  We will also provide an option not to save the HTML content on our server.</p>
<p>Eventually, there will be a non-central version of DamnIT that people can download and install on their own.  This will avoid all the security issues and perform better because it won&#8217;t have to be cross domain.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

