HTML Cleaner "Spermicide"
Jan. 22nd, 2006 11:09 pm![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
While we could discuss forever that HttpOnly isn't a complete solution for all
attack instances, that's not what matters. It's like saying, "Well, condoms
don't _always_ work, so let's just not use anything!" HttpOnly does work most
of the time, especially for stopping what our HTML/CSS spermicide doesn't.
-- Brad, https://bugzilla.mozilla.org/show_bug.cgi?id=178993#c49
(no subject)
Date: 2006-01-23 04:54 am (UTC)That sentiment is generally the reason behind arguments against impartial solutions -- a false sense of security can sometimes be worse than no security at all.
(no subject)
From:(no subject)
From:(no subject)
From: