SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : How high will Microsoft fly? -- Ignore unavailable to you. Want to Upgrade?


To: Charles Tutt who wrote (63688)12/12/2001 6:09:35 PM
From: dybdahl  Respond to of 74651
 
Not quite. Microsoft tried to address several real problems:

1) That the file name is not transferred as part of a http file download.
2) That many web servers in the early web didn't transfer correct mime types for the files they contained.

The problem is, that the solution violates the standards and doesn't work properly today, especially not in heterogene environments with Macintoshes and Linux clients. But in order to maintain backwards compatibility, they have kept this erroneous file type detection, and now it seems that testing it for security hasn't been part of Microsoft's test suite. Microsoft still treats security as a PR problem, not a design problem.

Lars.