2 ms·
To me it looks like the actual security problem is that the browser does not trust the server, using its own heuristics instead. Mozilla asserts that as well:
by erlehmann_ 10y ago
To me it looks like the actual security problem is that the browser does not trust the server, using its own heuristics instead. Mozilla asserts that as well:
> While MIME sniffing increases the web experience for the majority of users, it also opens up an attack vector known as MIME confusion attack.
The header tells the browser to stop shenanigans and behave.