Re: security impact of dropping charset default

On Thu, 24 Jan 2008, Mark Nottingham wrote:

> Are you saying that you're against adding a sentence or two to Security 
> Considerations about this issue? So far, I've seen pretty strong support for 
> doing so from a variety of people.

It would be a nice addition to describe the issue in general, not only for 
HTML content, when UA are into the "content sniffing" business. It fits 
well in the security section of HTTP.

The specific case of HTML needs also to be explained, but has its place in 
a document reserved for browser implementors. I am pretty sure there is 
already one that can be extended that way.

-- 
Baroula que barouleras, au tiéu toujou t'entourneras.

         ~~Yves

Received on Thursday, 24 January 2008 16:30:39 UTC