W3C home > Mailing lists > Public > whatwg@whatwg.org > December 2009

[whatwg] Uploading directories of files

From: L. David Baron <dbaron@dbaron.org>
Date: Sun, 13 Dec 2009 00:01:25 -0800
Message-ID: <20091213080125.GA6413@pickering.dbaron.org>
On Friday 2009-12-11 02:17 -0800, Jeremy Orlow wrote:
> But regardless.....I don't think you could argue that having _some_ path
> information is worse than _none_, right?

Many of those who commented in
https://bugzilla.mozilla.org/show_bug.cgi?id=143220 and its
duplicates would disagree.  Users may not expect the act of
uploading a file to give the Web site details of their file system
structure.  There also seems to be some concern that those details
may provide information useful to an attacker.


L. David Baron                                 http://dbaron.org/
Mozilla Corporation                       http://www.mozilla.com/
Received on Sunday, 13 December 2009 00:01:25 UTC

This archive was generated by hypermail 2.3.1 : Monday, 13 April 2015 23:08:54 UTC