One of the things I have taken from the IE XSS Filter project is a healthy fear of legacy character sets. If you’ve followed Chris Weber, Scott Stender, or Yosuke