Re: IE8 security features

2008-07-10 Thread Kaushal Varshney
"Gervase Markham" <[EMAIL PROTECTED]> wrote in message news:[EMAIL PROTECTED] > Robert O'Callahan wrote in mozilla.dev.planning: >> There are some posts in the IE blog about IE8 security features. >> http://blogs.msdn.com/ie/ >> Most of it is just trying to catch up to Firefox 3. Three things that

Re: IE8 security features

2008-07-10 Thread Kaushal Varshney
"Gervase Markham" <[EMAIL PROTECTED]> wrote in message * news:<[EMAIL PROTECTED]>*> ... > Robert O'Callahan wrote in mozilla.dev.planning: > > There are some posts in the IE blog about IE8 security features. > > *http://blogs.msdn.com/ie/* > > Most of it is just tryi

Re: Site Security Policy

2008-07-10 Thread glenn . wurster
Thought I'd get involved in the conversation (full disclosure: I'm involved with the SOMA paper that Terri has been discussing). The point of both lines of work (both yours and ours) is to attempt to restrict the number of XSS and XSRF vulnerabilities which exist in the web today. We have gone ab

Re: IE8 security features

2008-07-10 Thread Gervase Markham
Mike Ter Louw wrote: > In the MSDN blog comments, Giorgio Maone links to documentation for a > similar feature of NoScript: > > http://noscript.net/features#xss Well, this describes what it does, but not how it does it, so it's not very helpful by itself. Of course, as NoScript is free software,