Re: [whatwg] Dealing with UI redress vulnerabilities inherent tothe current web

<11e306600809262049x7f731dd6ld15879e09d7f4122@mail.gmail.com>

Current votes: None.

------=_Part_27599_31101416.1222487394649
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

On Sat, Sep 27, 2008 at 3:17 PM, Richard's Hotmail <maher_rj@hotmail.com>wrote:

> https://jdk6.dev.java.net/plugin2/
> http://weblogs.java.net/blog/joshy/archive/2008/05/java_doodle_cro.html
>
>

We have a W3C spec for the latter called Access Controls, which is a good
deal more secure than Java/Flash's crossdomain.xml.

Anyway, the fact that Java is evolving some sort of cross-domain capability
doesn't help make the argument that the Java 1.0 same-origin sandbox model
is an adequate solution to everything.

Rob