It seems to me
That adverts present the biggest risk for XSS attacks, particularly ones that are allowed to run scripts just to make them more intrusive (a la 'popovers' and 'pupups'). I see no problem with ads that are bog standard GIFs but anything else, especially flash is unnecessary. My recommendation to everyone would be to run FF with AdBlock and not see any of them anyway. problem is, if everyone did this, we'd have to find some new way of funding the internet. Then again, other than El Reg we probably wouldn't be missing much...


