Nonetheless, you really should make sure that input is sanitized. XSS attacks are a nasty thing.
Reply on news.ycombinator.com