Comment 40 for bug 44062

Revision history for this message
In , Darin-moz (darin-moz) wrote :

I think that:

1) the standard has a major hole in it that cannot be fixed by the browser alone.
2) we should give servers the tools necessary to patch this hole.
3) then servers that care will patch the hole.

If a side-effect of this is that sites can better protect their users' privacy &
security when they navigate with Mozilla-based browsers, then so be it! ;-)

Moreover, as we know, this is not a new security issue. This has been known
about for years. Therefore, I'm not sure that attempting an ad-hoc, partial
browser-only fix is worth the effort. IMO, it would be better to implement a
solution that will solve the problem well in the long-term.