Henrik Nordstrom wrote: > > But the security issues related message bodies deserves a separate > discussion in what can be done in the specs to improve the situation. Security issues are caused by implementors. Please reread the Watchfire report carefully to observe all the ways an implementor can do so. But don't cloud the spec solving a non-issue which the spec clearly defined for interoperability. No conforming server or proxy agent was subject to the HTTP Request Splitting vulnerabilities. (Which is to say all were, but it was very clear in each case what the implementor had done wrong.)Received on Wednesday, 17 January 2007 02:48:07 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 4 October 2011 12:13:57 GMT