I should find someone to write about the arbitrary JavaScript execution problem
@audrey that used to really confuse the shit out of me