<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Thoughts on Declaring Security Policies</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/25/9804105.aspx</link><description>My thoughts about Mozilla's Content Security Policy proposal were just published over on the IEBlog. I actually have quite a bit more to say (at even greater length :-) about declarative security mechanisms, and some more technical feedback specific to</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Thoughts on Declaring Security Policies</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/25/9804105.aspx#9836200</link><pubDate>Fri, 17 Jul 2009 01:40:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9836200</guid><dc:creator>EricLaw [ex-MSFT]</dc:creator><description>&lt;p&gt;Ian Hickson, editor of HTML5, weighed in with his feedback here: &lt;a rel="nofollow" target="_new" href="http://groups.google.com/group/mozilla.dev.security/browse_thread/thread/87ebe5cb9735d8ca#"&gt;http://groups.google.com/group/mozilla.dev.security/browse_thread/thread/87ebe5cb9735d8ca#&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;His conclusion? &amp;nbsp;&amp;quot;I think CSP is orders of magnitude too complicated to be a successful security mechanism on the Web. &amp;quot;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9836200" width="1" height="1"&gt;</description></item><item><title>re: Thoughts on Declaring Security Policies</title><link>http://blogs.msdn.com/b/ieinternals/archive/2009/06/25/9804105.aspx#9818355</link><pubDate>Mon, 06 Jul 2009 03:33:25 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9818355</guid><dc:creator>EricLaw [ex-MSFT]</dc:creator><description>&lt;p&gt;The Mozilla folks requested that I post my detailed feedback publicly. &amp;nbsp;If you're interested in the gory details, you can find them here:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://groups.google.com/group/mozilla.dev.security/browse_thread/thread/571f1495e6ccf822#"&gt;http://groups.google.com/group/mozilla.dev.security/browse_thread/thread/571f1495e6ccf822#&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9818355" width="1" height="1"&gt;</description></item></channel></rss>