[cap-talk] Webkeys vs. the web
Raoul Duke
raould at gmail.com
Wed Apr 1 18:14:12 EDT 2009
> The URL that is in the browser's address bar is dangerous because users
> share it with the expectation that it, by itself, conveys no authority.
> Thus any URLs that *do*, by themselves, convey authority must not be
> displayed in a browser's address bar.
if that is the case, it doesn't seem strong enough to me, because it
seems like the danger is arbitrarily great. packet sniffers can get
those plain text caps no problem, no?
sincerely.
More information about the cap-talk
mailing list