I'm not quite sure I follow the theat model here?<p>> But wait... can't someone come along then and just create a more lenient policy called default? No! That will throw an exception!<p>Who is "someone" in this situation? And why are they able to execute arbitrary JavaScript code in the user's browser, yet the user is somehow protected by a string sanitization policy?