On Fri, 17 Jul 2009, Amos Jeffries wrote: > > Um, okay. Have a read of this alternate Spec and see if you can stil > find the security hole you are woried about:
I don't understand in what way it substantially differs from what the spec says today. There are minor differences in wording, but other than that, and other than the requirement that two TCP connections be established to port 80 when using port 80 instead of just one, it seems equivalent. Could you elaborate on what the important difference you had in mind is? -- Ian Hickson U+1047E )\._.,--....,'``. fL http://ln.hixie.ch/ U+263A /, _.. \ _\ ;`._ ,. Things that are impossible just take longer. `._.-(,_..'--(,_..'`-.;.'
