Ben Vinegar Software engineer at Disqus Co-author, Third-party JavaScript (Manning) Once ate 7 McDonald's cheeseburgers in one sitting Implemented Content Security Policy in Disqus Cross-Site Scripting (XSS) This is still a problem Cross-site scripting (XSS) Vulnerability where attacker injects JavaScript code into a web document <?php $name = $_GET['name']; echo "Welcome $name"; ?> GET http://urs