Newsgroups: mozilla.dev.security
From: Lucas Adamski <lu...@mozilla.com>
Date: Fri, 10 Jul 2009 12:18:12 -0700
Local: Fri, Jul 10 2009 3:18 pm
Subject: Re: Content Security Policy Spec questions and feedback
With security, its safer (and more accurate) to assume compatibility
breakage than not. Its not just syntax that can change but the rules themselves. For example if we identify new vectors for code injection, we might have to block additional APIs thus breaking sites that would otherwise effectively support CSP without any change in syntax. Even something as relatively simple to reason about like HTTP itself On Jul 8, 2009, at 9:21 AM, Gervase Markham wrote: > So the versioning in the UA is to guard against a policy syntax > I don't think the risk of needing a breaking syntax change is worth >> The other approach is to version the response, a few extra bytes only > But this scary scenario fails to take into account the frankly tiny You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||