What is the difference between AntiXss.HtmlEncode and HttpUtility.HtmlEncode?

Viewed 27831

I just ran across a question with an answer suggesting the AntiXss library to avoid cross site scripting. Sounded interesting, reading the msdn blog, it appears to just provide an HtmlEncode() method. But I already use HttpUtility.HtmlEncode().

Why would I want to use AntiXss.HtmlEncode over HttpUtility.HtmlEncode?

Indeed, I am not the first to ask this question. And, indeed, Google turns up some answers, mainly

  • A white-list instead of black-list approach
  • A 0.1ms performance improvement

Well, that's nice, but what does it mean for me? I don't care so much about the performance of 0.1ms and I don't really feel like downloading and adding another library dependency for functionality that I already have.

Are there examples of cases where the AntiXss implementation would prevent an attack that the HttpUtility implementation would not?

If I continue to use the HttpUtility implementation, am I at risk? What about this 'bug'?

5 Answers
Related