On 12/12/11 20:07, Richard L. Barnes wrote: > In fact, it doesn't look like they're even processing the onload > handler for the <body> element (except for Gmail). That black line > you see is a collapsed <div>, and it should be hidden on load. Maybe > MUAs just aren't supporting Javascript? --Richard
It's not that they don't support it (Thunderbird is half-written in JavaScript!), it's that they turn it off. It's been disabled by default since at least Thunderbird 2. Doing so leads to a large reduction in attack surface. Gerv _______________________________________________ websec mailing list [email protected] https://www.ietf.org/mailman/listinfo/websec
