Re: security impact of dropping charset default [Re: text/* types and charset defaults [i20]]

Roy T. Fielding wrote:

> I think it would be easier to simply say that (i.e., "The charset
> guessing algorithm MUST exclude 7-bit character encodings other
> than US-ASCII.  In particular, UTF-7 MUST NOT be guessed.")

 From Asian point of view, it is almost unacceptable to exclude all
ISO-2022-* charsets which use ESC as an escape character.
It is not historic, is better than 8-bit charsets in some context
(because these explicitly declare charset using ISO-2022 defined sequences),
and is ASCII upper-compatible by the above definition.

-- 
Yutaka OIWA, Ph.D.                                       Research Scientist
                             Research Center for Information Security (RCIS)
     National Institute of Advanced Industrial Science and Technology (AIST)
                       Mail addresses: <y.oiwa@aist.go.jp>, <yutaka@oiwa.jp>
OpenPGP: id[995DD3E1] fp[3C21 17D0 D953 77D3 02D7 4FEC 4754 40C1 995D D3E1]

Received on Wednesday, 23 January 2008 03:05:09 UTC