Posted by A. S. Milnes on 03/30/05 12:08
On Wed, 2005-03-30 at 04:59, Richard Lynch wrote:
> Please reference their publications, if possible.
At hand immediately I have:-
PHP and MySQL Web Development 3rd edition by Luke Welling (Senior Web
Developer at MySQL) and Laura Thomson, published by
www.developers-library.com.
> It's just plain BAD security to trust this value for any real-world usage.
Surely it's part of the toolkit - you can filter out people sending
dangerous stuff if they are not that sophisticated. I would never want
to rely on one line of defence.
> And it's made meaningless by the browsers not standardizing what they send
> anyway.
It's an interesting point which I will need to investigate further.
Alan
[Back to original message]
|