Brad Fitzpatrick (brad) wrote,
Brad Fitzpatrick

Firefox bugs

My beef with Firefox:

Firefox doesn't have HttpOnly cookies, even though LiveJournal had avva write a patch for Mozilla over a year ago:

Javascript in external CSS doesn't have the same-origin restrictions that Internet Explorer does, allowing untrusted remote CSS to do malicious things:

See my comment there for more information.

Either one of these would've prevented us from going with one-domain-per-user (our new URL scheme), and the forthcoming cookie changes where we have master cookies and per-domain cookies that are signed by the master cookie.

Fun, but a pain in the ass too.
Tags: javascript, security, tech, work
