On 20 January 2010, I sent comments about draft-abarth-mime-sniff-03: http://www.ietf.org/mail-archive/web/apps-discuss/current/msg01250.html
to the "apps discuss" mailing list; there were responses, but I disagree with the responses, in that I disagree that the goal of having all agents sniff identically is possible or even a realistic or important goal. Minimizing the opportunities for unnecessary privilege escalation seems like a much more important goal. However, I urge the websec working group to review the comments and the responses. In addition http://tools.ietf.org/html/draft-masinter-mime-web-info sections 3.3, 5.1.1 and 5.2 make specific comments about, and recommendations for, sniffing and its interactions with the MIME registry. Larry -- http://larry.masinter.net From: [email protected] [mailto:[email protected]] On Behalf Of =JeffH Sent: Wednesday, March 30, 2011 3:44 AM To: IETF WebSec WG; Tobias Gondrom Subject: [websec] slides: hodges-ietf-80-hodges-framework-reqs-Status
_______________________________________________ websec mailing list [email protected] https://www.ietf.org/mailman/listinfo/websec
