Jupiter Jones [MVP]
Guest
Posts: n/a
 
Re: Mad fools
Posted: 09-01-2006, 06:02 AM
Beta in itself should be reason enough to deny access.
The server could handle it, but for security reasons some choose not to.
Similarly some prevent use of older browsers.
Nothing suggested they should not also be concerned about invalid requests.
It is not either/or.
Preventing access with a Beta product ads another layer the integrity of the
system.

--
Jupiter Jones [MVP]
http://www3.telus.net/dandemar
http://www.dts-l.org


"Homer J. Simpson" <root@127.0.0.1> wrote in message
news:uWTibVQzGHA.4576@TK2MSFTNGP06.phx.gbl...
> Define the criteria by which a bank should "like" a client's software or
> not, and what should be done about it.
>
> A secure server should be able to handle any request coming from any
> client, whether the end user is using an RTM browser, a beta, or a
> home-grown one trying that's trying to impersonate something else. Anyone
> writing server-side code should be more concerned with rejecting invalid
> requests than verifying whether the client's browser is a beta or not.

Reply With Quote
Homer J. Simpson
Guest
Posts: n/a
 
Re: Mad fools
Posted: 09-01-2006, 04:01 PM
> Preventing access with a Beta product ads another layer the integrity of
> the system.
With all due respect, I don't buy that at all. I hope you're not suggesting
that the traditional browser sniffing methods add anything to security. If
so, I might as well write my own "browser" that identifies itself as IE6 and
start attacking one of those IE-only sites...


Reply With Quote
Jupiter Jones [MVP]
Guest
Posts: n/a
 
Re: Mad fools
Posted: 09-02-2006, 12:14 AM
Not allowing a known Beta adds another layer of security.
In and of itself it adds little, but combined with other layers helps keep
the computer secure.

Go ahead and write if you are able...

--
Jupiter Jones [MVP]
http://www3.telus.net/dandemar
http://www.dts-l.org


"Homer J. Simpson" <root@127.0.0.1> wrote in message
news:ODceNedzGHA.3568@TK2MSFTNGP03.phx.gbl...
> With all due respect, I don't buy that at all. I hope you're not
> suggesting that the traditional browser sniffing methods add anything to
> security. If so, I might as well write my own "browser" that identifies
> itself as IE6 and start attacking one of those IE-only sites...

Reply With Quote
Homer J. Simpson
Guest
Posts: n/a
 
Re: Mad fools
Posted: 09-14-2006, 05:47 PM
> Not allowing a known Beta adds another layer of security.
> In and of itself it adds little, but combined with other layers helps keep
> the computer secure.
>
> Go ahead and write if you are able...
Even if I had the time, inclination, or anything to prove to yourself or
others, what exactly would that prove?


Reply With Quote
wno158
Guest
Posts: n/a
 
Re: Mad fools
Posted: 09-16-2006, 08:37 AM
> Neither does ..., CitiBank ... will though.
>
citibank.com works, but citibank.de does not (I'm German.) - and does also
not work with Firefox on Vista.
So we'll have to wait for RC2 or a change on the Citibank servers.

Walter
Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Fools rush in where angels fear to tread. Bob Windows XP Setup 0 11-21-2003 05:46 PM


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90