Re: signed scripts and security changes in 2.0.0.15?

2008-08-15 Thread Jonas Sicking
Nelson Bolyard wrote: > Jonas Sicking wrote, On 2008-08-13 10:32: >> Nelson Bolyard wrote: >>> Jonas Sicking wrote, On 2008-08-11 20:33: >>> I would strongly recommend against using signed files at all. It's something that we want to get rid of since the security model is so poor. >>> Jo

Re: Site Security Policy

2008-08-15 Thread bsterne
On Jul 12, 10:35 am, "Evert | Rooftop" <[EMAIL PROTECTED]> wrote: > Sorry if this was already brought up in this thread (or if its a > closed subject), but using headers vs. a policy file is a bad idea, > for the following reasons: > > * Allows caching > * Allows usage of the policy on a site where