Mark Martin wrote: > Darren J Moffat wrote: >> >> Also this is really no different several other similar cases with SSL. >> >> If HTTPS is not enabled then I will derail this case and call for a >> vote. >> > > I don't think the only issue is the lack of a handy, well known cert > repository; the fact that the underlying implementation doesn't > validate properly would probably surprise folks. > > The choices that I saw were: > a) Deliver with HTTPS disabled by default. Principle of least > astonishment. > b) Deliver with (incomplete and ostensibly unsafe) HTTPS enabled by > default. > > If you're insisting on B, how do you advise managing the gap? Log a > bug? Document a warning? Assume developers will be diligent or just > know? Apologies for the reply to self, but I forgot to mention that option A was the behavior from the first case, and since the classification was changed from consolidation private, I believe the exposure is increased.
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/409 FastTrack ... Mark Martin
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/409 FastT... Alfred Peng
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/409 F... Mark Martin
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/4... Alfred Peng
- [desktop-discuss] WebKit 1.1.x [LSARC/20... Mark Martin
- [desktop-discuss] WebKit 1.1.x [LSARC/20... Alfred Peng
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/409 FastTrack ... Brian Cameron
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/409 FastT... Brian Cameron
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/409 F... Darren J Moffat
- [desktop-discuss] WebKit 1.1.x [LSARC/2009/4... Mark Martin
- [desktop-discuss] WebKit 1.1.x [LSARC/20... Mark Martin
- [desktop-discuss] WebKit 1.1.x [LSARC/20... Darren J Moffat
- [desktop-discuss] WebKit 1.1.x [LSA... Brian Cameron
- [desktop-discuss] WebKit 1.1.x [LSA... Alfred Peng
- [desktop-discuss] WebKit 1.1.x ... Hugh McIntyre
- [desktop-discuss] WebKit 1.1.x ... Alfred Peng
- [desktop-discuss] WebKit 1.1.x ... Darren J Moffat
- [desktop-discuss] WebKit 1.1.x ... Mark Martin
- [desktop-discuss] WebKit 1.1.x ... Alfred Peng
- [desktop-discuss] WebKit 1.1.x ... Matt Lewandowsky
- [desktop-discuss] WebKit 1.1.x ... Darren J Moffat
