AJAX e segurança

Um pequeno artigo com uma série de pointers interessantes sobre o tema:

GWT: Advanced AJAX Security
http://campustechnology.com/articles/2008/01/gwt-advanced-ajax-security.aspx

um pequeno excerto:
"In this talk, Hoffman demonstrated advanced attacks against AJAX applications, including manipulating client-side logic, defeating logic protection techniques, function hijacking (client-side code being changed), JavaScript Object Notation (JSON) hijacking and denial of service attacks. He discussed the susceptibility of GWT applications to these kinds of attacks and compared GWT security features to other AJAX frameworks, such as Prototype and Dojo. He ended by talking about hacking Google Gears, an open source browser extension that lets developers create Web applications that can run offline."