More Cross Site Scripting in Google GoogleにXSSな穴があるよ、という事実より、それにまつわる感想の方が気になった。 But disclosure is such an ugly beast. While talking to one web app security expert today who shall remain unnamed, he said that he rarely discloses vulnerabilities anymore, because it’s just not worth his time. He’s not getting paid for it, and it’s not helpful to him to disclose it. So in liue of that, Google gets bad