Re: Today's transition for www.ietf.org

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 





On Sun, Jan 14, 2018 at 9:21 AM, Keith Moore <moore@xxxxxxxxxxxxxxxxxxxx> wrote:

On 01/13/2018 07:14 PM, Eric Rescorla wrote:


 It would be best to kill _javascript_ entirely,
given that it's the vector for a myriad of attacks and therefore that
it's become a best practice to disable it in browsers.

I would characterize this more as a minority view than a best practice. _javascript_
is ubiquitous throughout the Web.

I would characterize it as both best practice and a minority view.   We should never assume that best practice is synonymous with widespread practice, especially where security is concerned.

Well, IETF typically measures best practice by consensus. What community do you believe this represents the consensus view of. I doubt, for instance, the Web security community.

-Ekr



Keith



[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]