Unfortunately, the existing option in the IE6+ Security Zones UI is both poorly named and does not really do what it implies.  Rather than turning off sniffing altogether, it modifies the behavior only in the case of an "ambiguous" MIME type.  Specifically, "text/plain" and IIRC "application/octet-stream."

The new authoritative=true attribute introduced for IE8 Beta-2, on the other hand, will be effective for all MIME types.  You can simply see what behavior change would result if IE were to universally change behavior by writing a small Fiddler ( response modification rule that sets the authoritative=true attribute for all HTTP responses.

Please do keep in mind, however, that most folks (even the ultra-web engaged on these lists) see but a small fraction of the web, especially considering private address space/intranets, etc.


Oh nice, I didn't know about that.  I've attached an (untested) patch
that I think turns off content sniffing in TOT Firefox for those that
would like to try this out.


