Weblog entry #261 for simonw

Microsoft Logic / Google focus
Posted by simonw on Fri 4 Jul 2008 at 14:01
Tags: none.
Content-Type: text/plain

Is plain text...

Microsoft sniff it, to see if it isn't. Their logic is that asking everyone who does it wrong to "fix their own servers" is too hard. So they introduce "authoritative=true" option to the Content-Type, thus asking all those who do it right to "fix their own servers".

I so hope it is April the 1st.

In other news Google tells me some web pages we are serving as "Content-Type: text/plain" for free hosting customers contains malicious JavaScript - surely some mistake here.

Whilst Google's attempts to clean up the web are laudable, client security has to be fixed by the software vendors. I think Google would better achieve its goal by detecting browsers with known security issues and recommending/insisting on an upgrade.

http://blogs.msdn.com/ie/archive/2005/02/01/364581.aspx

http://blogs.msdn.com/ie/archive/2008/07/02/ie8-security-part-v-comprehensive-protection.aspx

I believe there is a registry setting to disable content sniffing in IE, but I would suggest not using IE. Firefox NoScript Add-on is your friend.

 

User Login

Username:

Password:

[ Advanced Login ]

Register Account

Quick Site Search