Hi,

I agree the patch is bullsh** as you call it but I've some mixed feelings
about it. The fact is that I also have some applications that stop working with
this patch but... having username and password in the URL doesn't seem to be a
good idea nowadays.

At the same time, there was some users "hacked" using URL hidding and this
patch protects those users. So, in that way it's a good thing. Well, I know
that problem was a IE bug, but still... I also don't want to start an anti-M$
discussion...

Moreover, username and password in the URL is been deprecated since RFC2616.
But that doens't mean you can't support it! Microsoft decided not do it anymore.

Two options: fix your website or don't install the patch.

I know my comments might not be a good help but as I wrote before, I also don't
know very well what to think about this..

Cheers
Jorge


On 10-Feb-2004 Matthias Hertzog wrote:
> Hi there!
> 
> Microsoft has released a IE patch Number 834489. This patch makes URLs like
> http://username:[EMAIL PROTECTED] unusable. Since we have a few
> applications (intranets, closed user groups, a.s.o) running which use this
> kind of verification, our customers are running into problems after applying
> this patch.
> 
> mhs has released informations at http://www.mhs.ch/mhsservices/patch.shtml
> (sorry, german only) and is currently informing customers affected by this.
> 
> Please don't start any "political" (Anti-MS) discussions now. I fully agree,
> that this MS patch is pure bullshit. I'm very interested in your points of
> view and possible _technical_ solutions in that.
> 
> Best wishes,
> Matthias
> 
> BTW: Microsoft's informations:
> http://support.microsoft.com/default.aspx?scid=kb;[LN];834489
> 
> M.H.
> 
> 
> ----------------------------------------------
> [EMAIL PROTECTED] Maillist-Archive:
> http://www.mail-archive.com/swinog%40swinog.ch/

-- 
Cybernet Switzerland
P.O. Box 825, Schaffhauserstr. 560, CH-8052 Zuerich
Tel +41 1 306 46 46, Fax +41 1 306 95 95
Jorge Morgado, Network Engineer, [EMAIL PROTECTED]
----------------------------------------------
[EMAIL PROTECTED] Maillist-Archive:
http://www.mail-archive.com/swinog%40swinog.ch/

Reply via email to