On CHOW: Bagel-related injuries on the rise
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 19 of 52:
Next »
« Previous
So did you.
"Why can't you give MS just a little bit of credit. They have
made a baby step toward improving security, but they are
still lambasted for the "way they have done it." Huh? What
were they supposed to do?"

Gosh. I don't know. maybe they could have done what every
other browser maker in the world has done since the end of
time. The problem isn't the "@" in the URL. It's that they
can't handle a nonprinting character. It causes the whole
rest of the URL string to disappear in the address field. All
other browser handle this problem effectively.

"Oh, I get it, fix the program so that something else does
not break. Sounds easy. Fix the program to allow the
ridiculously insecure practice of including log-on
credentials in the very insecure URL and yet prevent
possible negative security implications."

You don't understand. Basic authentication is equally
insecure whether you include the authentication
information in the URL or not, but under many
circumstances, basic is good enough, and much better than
nothing. Furthermore, IE STILL DOES allow authentication
information to be included in the URL. That's what happens
if it's part of the query string. It's less safe than using post
with encryption, but, again, sometimes it's good enough.
Posted by: Immanuel Tranz-Mischen   Posted on: 02/05/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

&itch..&itch...&itch  LinuxHippie | 02/04/04
Another way to say that  Chad_z | 02/04/04
here's a novell idea...  ryusen | 02/05/04
yea thats too bad  JoeMama_z | 02/04/04
when you use a browser  JWatson77 | 02/04/04
Whats your point?  rschror | 02/04/04
your pointless  stephen732@... | 02/04/04
Do a little research.  Immanuel Tranz-Mischen | 02/04/04
not until ms play fair  JWatson77 | 02/05/04
Please....  DarbyOhara | 02/05/04
I use Win2k pimple face  JWatson77 | 02/05/04
Umm...  TrollSlayer | 02/05/04
this was never a feature  JWatson77 | 02/04/04
Veeeeery Surprising  Bobby Sskcat | 02/04/04
This isn't the first time.  Immanuel Tranz-Mischen | 02/04/04
Thanks to wrong doers  Christian_<>< | 02/04/04
Message has been deleted.  Cardinal_Bill | 02/04/04
You left something out  vferrara | 02/05/04
So did you.  Immanuel Tranz-Mischen | 02/05/04
YOU left something out  B_HI | 02/11/04
Didn't fix a damned thing.  Yen_z | 02/04/04
Smiley Face got me.  Yen_z | 02/04/04
I tried out several of them  jfrankcarr | 02/04/04
MS putting ... security first (!)  michael-t | 02/04/04
What a stinkin' load...  TrollSlayer | 02/05/04
Addendum  TrollSlayer | 02/05/04
TrollSlayer??? More like Troll  PmAc_z | 02/05/04
Riiiiiiiiiiiiiggggggghhhhhtttt!  TrollSlayer | 02/05/04
Not quite...  wolf_z | 02/05/04
You are correct...  TrollSlayer | 02/05/04
One more thing!  TrollSlayer | 02/05/04
And another thing!  TrollSlayer | 02/05/04
We need a hero  BXLE | 02/05/04
Lazy developers  dscherf | 02/05/04
lazy  BXLE | 02/05/04
It was a jab  dscherf | 02/05/04
It is about time!  ShadeTree | 02/05/04
Really  russ@... | 02/05/04
What???  ShadeTree | 02/05/04
Flawed? Maybe...  Brett04_z | 02/05/04
Not exactly  MarcB_z | 02/05/04
Oh Well........  tslocum7 | 02/05/04
Security??????????????????????????  russ@... | 02/05/04
great - break (more) standards  bschlatzer@... | 02/05/04
IE Security Patch  Jaytmoon | 02/05/04
Stop Using IE! There Are Much Better Browsers Out There  brenthawkinsmd | 02/05/04
IE Phishing Fix via Feature Removal is a Hoax  Davinci_J | 02/05/04
Interesting  jfrankcarr | 02/06/04
Its Broke?  WillGates | 02/05/04
IE the best and only web-browser  Christian_<>< | 02/05/04
IE is crap.  Squire72 | 02/08/04
IE is no better actually  Aragorn_z | 02/09/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

IT Solutions for 2010

  • Get cost-effective strategies and roadmaps on the most important issues facing IT leaders in 2010! Learn how to easily cut costs and deliver greater efficiency starting with your database, IT compliance management and data center. Visit the IT Leaders Dashboard. Visit the IT Leaders Dashboard.
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline