<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta content="text/html;charset=UTF-8" http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
Pat Patterson wrote:
<blockquote cite="mid:3E64A1A9-0AAE-45B7-ACBC-FF291F9E3E65@sun.com"
type="cite">I don't understand this from section 11.5.2:
<div>
<div>Surely, if an attacker gained control of the HTTP URL, he would
be free to redirect to an endpoint of his choosing, a clear reduction
in security. Am I missing something?</div>
</div>
</blockquote>
HTTP URL = Web site? <br>
HTTP = DNS?<br>
<br>
Surely, if an attacker gained control of the HTTP<b>S</b> URL this
would be a clear reduction in
security.<br>
<br>
Guess you don't miss anything.<br>
<br>
<div class="moz-signature">-- <br>
<table border="0" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td colspan="2">Regards </td>
</tr>
<tr>
<td colspan="2"> </td>
</tr>
<tr>
<td>Signer: </td>
<td>Eddy Nigg, <a href="http://www.startcom.org">StartCom Ltd.</a></td>
</tr>
<tr>
<td>Jabber: </td>
<td><a href="xmpp:startcom@startcom.org">startcom@startcom.org</a></td>
</tr>
<tr>
<td>Blog: </td>
<td><a href="http://blog.startcom.org">Join the Revolution!</a></td>
</tr>
<tr>
<td>Phone: </td>
<td>+1.213.341.0390</td>
</tr>
<tr>
<td colspan="2"> </td>
</tr>
</tbody>
</table>
</div>
</body>
</html>