To be clear, I'm not going back from the point we reached at the F2F. I am compromising (will little, if anything, in return). I am beaten down. I think the minimum security measure we could take is to cryptographically sign any downloadable transform. I don't know if that will interfere with execution or not (needs investigation, but not by me). I do know that extant GRDDL agents don't check that. But at least they could be upgraded. As for system concerns...well, I guess if the W3C doesn't care, then I'll shut up. Cheers, Bijan.Received on Thursday, 26 February 2009 09:11:31 GMT
This archive was generated by hypermail 2.2.0+W3C-0.50 : Thursday, 26 February 2009 09:11:31 GMT