logoalt Hacker News

WatchDogtoday at 5:42 AM0 repliesview on HN

If it were vulnerable to XSS, why would you even want it properly signed by a CA? People almost never inspect the certificates of working websites, the only time they might look at it is when it fails validation.