On 20 January 2010, I sent comments about draft-abarth-mime-sniff-03:
http://www.ietf.org/mail-archive/web/apps-discuss/current/msg01250.html

to the "apps discuss" mailing list; there were responses, but  I disagree with 
the responses, in that I disagree that the goal of having all agents sniff 
identically is possible or even a realistic or important goal. Minimizing the 
opportunities for unnecessary privilege escalation seems like a much more 
important goal.

However, I urge the websec working group to review the comments and the 
responses.

In addition

http://tools.ietf.org/html/draft-masinter-mime-web-info

sections 3.3, 5.1.1 and 5.2 make specific comments about, and recommendations 
for, sniffing and its interactions with the MIME registry.


Larry
--
http://larry.masinter.net

From: [email protected] [mailto:[email protected]] On Behalf Of 
=JeffH
Sent: Wednesday, March 30, 2011 3:44 AM
To: IETF WebSec WG; Tobias Gondrom
Subject: [websec] slides: hodges-ietf-80-hodges-framework-reqs-Status


_______________________________________________
websec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/websec

Reply via email to