W3C home > Mailing lists > Public > whatwg@whatwg.org > December 2009

[whatwg] Uploading directories of files

From: L. David Baron <dbaron@dbaron.org>
Date: Sun, 13 Dec 2009 00:01:25 -0800
Message-ID: <20091213080125.GA6413@pickering.dbaron.org>
On Friday 2009-12-11 02:17 -0800, Jeremy Orlow wrote:
> But regardless.....I don't think you could argue that having _some_ path
> information is worse than _none_, right?

Many of those who commented in
https://bugzilla.mozilla.org/show_bug.cgi?id=143220 and its
duplicates would disagree.  Users may not expect the act of
uploading a file to give the Web site details of their file system
structure.  There also seems to be some concern that those details
may provide information useful to an attacker.

-David

-- 
L. David Baron                                 http://dbaron.org/
Mozilla Corporation                       http://www.mozilla.com/
Received on Sunday, 13 December 2009 00:01:25 UTC

This archive was generated by hypermail 2.3.1 : Monday, 13 April 2015 23:08:54 UTC