Re: [whatwg] Domain transfer security

2012-08-29 Thread Ian Hickson
On Tue, 12 Jun 2012, Simon Brown wrote: I have thought of a possible security problem that may be reduced with a change to the specifications (though I'm not sure exactly how). 1. An attacker has control of a popular site. 2. The attacker buys a valuable domain. 3. The attacker creates a

[whatwg] Domain transfer security

2012-06-12 Thread Simon Brown
I have thought of a possible security problem that may be reduced with a change to the specifications (though I'm not sure exactly how). 1. An attacker has control of a popular site. 2. The attacker buys a valuable domain. 3. The attacker creates a page on the site that sends all