In [1], it's mentioned that:

"Furthermore, as a security measure, prefetching of embedded link hostnames is 
not done from documents loaded over https. If you want to allow it in that 
context too, just set the preference network.dns.disablePrefetchFromHTTPS to 
true."

Can someone explain the security concerns with DNS prefetching from a HTTPS 
site?


- Bil


[1] http://bitsup.blogspot.com/2008/11/dns-prefetching-for-firefox.html

_______________________________________________
dev-security mailing list
dev-security@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security

Reply via email to