[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: Open Platform

  • From: Michael Kay <mike@saxonica.com>
  • To: xml-dev@lists.xml.org
  • Date: Tue, 14 Dec 2010 09:10:33 +0000

Re:  Open Platform
On 14/12/2010 03:36, Bjoern Hoehrmann wrote:
> * Michael Kay wrote:
>> Security restrictions in terms of what resources are accessible are of
>> course reasonable, though as far as I can see the cross-site-scripting
>> rules seem to be about as relevant to the real threat model as the
>> theatrical checks performed in airport security halls.
> It is common for web sites to discriminate based on client IP addresses.
> If I know for instance that some organization serves documents on its
> site that are only available to its members, and know the site is con-
> figured to require no further authentication for requests that come from
> within a member's network, I can gain access to those documents simply
> by setting up an advertisement, which sooner or later would be shown to
> someone from within such a network, which then sends me the documents.
I'm not quite sure whether your intent was to agree with me or disagree 
with me. The way I read your comment, you are agreeing with me that the 
current security model is a joke.

Michael Kay

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
First Name
Last Name
Subscribe in XML format
RSS 2.0
Atom 0.3

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.

Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.