Re: [tahoe-dev] How to use Caja to solve the same-origin policy hazard (hosting both webapps and untrusted content in Tahoe)

2011-07-30 Thread Kevin Reid
On Jul 30, 2011, at 4:50, Greg Troxel wrote: In your worldview, are there multiple WUIs? I can see the desire to use tahoe as a backing store for a web server, but until there are redundant WUIs and the client can select among them - I don't see the point compared to just running apache

Re: [tahoe-dev] How to use Caja to solve the same-origin policy hazard (hosting both webapps and untrusted content in Tahoe)

2011-07-30 Thread Zooko O'Whielacronx
Dear Kevin: Your letter fills me with internal conflict! On the one hand I'm delighted because what you propose is not only the best way to further protect against the dangers of looking at files stored inTahoe-LAFS through a web browser, but it also opens up the possibility of even better

Re: [tahoe-dev] How to use Caja to solve the same-origin policy hazard (hosting both webapps and untrusted content in Tahoe)

2011-07-30 Thread Brian Warner
On 7/29/11 5:39 PM, Kevin Reid wrote: Given the two origins, the only way you are in danger is if you have two “raw” (from origin #2) documents open in your browser at once The tab's history is also an angle of attack, so I think another danger is to open two different documents in sequence in