CARVIEW |
Select Language
HTTP/2 301
date: Sat, 11 Oct 2025 09:20:35 GMT
content-type: text/html; charset=ISO-8859-1
location: https://lists.w3.org/Archives/Public/public-wsc-wg/2008Jan/0192.html
cf-ray: 98cd4849891725e0-BLR
cache-control: max-age=21600
expires: Sat, 11 Oct 2025 15:20:34 GMT
x-backend: www-mirrors
x-request-id: 98cd4849891725e0
strict-transport-security: max-age=15552000; includeSubdomains; preload
content-security-policy: frame-ancestors 'self' https://cms.w3.org/ https://cms-dev.w3.org/; upgrade-insecure-requests
cf-cache-status: EXPIRED
set-cookie: __cf_bm=o.ZTA_wlA4Sjv1iJ4CComo6blnbJyCnep6ll2R8ZykE-1760174435-1.0.1.1-JtGeRpz4oxWjfjoaLq3eWzLC.AAKP8isRXN0Fe54PlXY0C6nB_dSBBO9Imkafcl.dB0ADNdY9Zpmn4rMLz86pcjX19PQMWAHm8ZXrQ.cv68; path=/; expires=Sat, 11-Oct-25 09:50:35 GMT; domain=.w3.org; HttpOnly; Secure; SameSite=None
vary: Accept-Encoding
server: cloudflare
alt-svc: h3=":443"; ma=86400
HTTP/2 200
date: Sat, 11 Oct 2025 09:20:35 GMT
content-type: text/html
content-encoding: gzip
last-modified: Thu, 13 Jul 2023 18:20:01 GMT
cache-control: max-age=2592000, public
expires: Mon, 10 Nov 2025 09:20:35 GMT
vary: Accept-Encoding
access-control-allow-origin: *
x-request-id: 98b3d66e4b2d4e3d
strict-transport-security: max-age=15552015; preload
x-frame-options: deny
x-xss-protection: 1; mode=block
cf-cache-status: MISS
server: cloudflare
cf-ray: 98cd484c0f04a9b7-BLR
alt-svc: h3=":443"; ma=86400
Re: ACTION-356: picture-in-picture attacks from Ian Fette on 2008-01-17 (public-wsc-wg@w3.org from January 2008)
Re: ACTION-356: picture-in-picture attacks
- From: Ian Fette <ifette@google.com>
- Date: Thu, 17 Jan 2008 10:36:59 -0800
- To: public-wsc-wg@w3.org
- Message-ID: <bbeaa26f0801171036q66f6a541xd65c5d1837a75eb3@mail.gmail.com>
I am not sure I fully understand the new text. "The editor bar MUST be displayed..." - is this saying it must be omnipresent, or that when it is displayed after being invoked by the user, it should have the customized theme etc? On Jan 17, 2008 9:54 AM, Thomas Roessler <tlr@w3.org> wrote: > > I've moved most of the Wiki text about picture-in-picture attacks > [1] into the current editor's draft: > > Many graphical user agents are vulnerable to picture-in-picture > attacks: Graphic and script elements within an HTML page are used > to simulate the look and feel of browser chrome. The attacker's > goal is to recreate a convincing mockup of the browser chrome > entirely within the content page, in order to provide (false) > indicators of security to the user. > > In these user agents, the editor bar MUST be displayed using a > theme customized to the user. The user selects this theme at > browser installation time and it remains forever the same. The > icon for the Contacts button MUST also be selected by the user at > installation time. > > -- > https://www.w3.org/2006/WSC/drafts/rec/rewrite.html#safebar-picture-in-picture > > 1. https://www.w3.org/2006/WSC/wiki/NoteTestCases > > I believe that ISSUE-126 can be closed. > > Regards, > -- > Thomas Roessler, W3C <tlr@w3.org> > >
Received on Thursday, 17 January 2008 18:37:10 UTC