Creating a crystal clear and pure Internet

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Tue Nov 27 23:23:04 UTC 2007


On Tue, 27 Nov 2007 22:04:23 +0100, Florian Weimer said:
> There's also the issue that you can't reliably tell data (which,
> presumably, does not need to be signed) from code.

And "active content" is what happens when you *intentionally* blur the data/
code distinction.

Unfortunately, it's (a) wildly popular with users and (b) usually horribly done
from a security standpoint.

Unfortunately, "Web 2.0" with its "glue stuff together" approach looks like
it's just going to make things even worse, as clueless developers wedge stuff
together with dangerous interactions and synergies....

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20071127/1561331a/attachment.sig>


More information about the NANOG mailing list