XSS is more than twenty years old by now and appears to still be alive and kicking. JavaScript alerts are popping left and right on a daily basis and bug bounty programs are drowning in submissions.And that is all despite our great efforts to get rid of this vulnerability class from each and every thinkable angle. What didn't we try to solve it. No?This talk will be an hour-long rant, paired with a stroll through the history of XSS and related issues. We will go back into the year 1998 and see how it all started, how things developed, what we tried to do against it and how hard we failed every single time. We will also look at the future and predict what is about to happen next.Mostly nothing - but at least that's good to know, right?We will not only look at our own failures but also see how the entire infrastructure and monetization of the web contributed to us being simply not capable or even just willing to fix XSS. And we might as well see if any of those behavioral and structural patterns can be compared to other human failures - and see if there is something we all can learn.One year ago, this talk was presented for the first time and boy, people were angry afterwards! Let's see where we arrived by now and if we can manage to trigger them again.