5 ms·
perhaps we need an RFC that defines this type of approach (pages "secured" behind easily guessable urls) as public information.
by lurker456 8y ago
perhaps we need an RFC that defines this type of approach (pages "secured" behind easily guessable urls) as public information.
- fouc 8y agoThat actually seems like a good idea to me. I wonder if there isn't already one? It'd be a good symbolic source of authority on issues like this. There could also be other RFCs covering our usage of the internet, and our expectations of what our rights are as internet users. Or perhaps stick that all in one "definitive" RFC.
- astrodust 8y agoInstead of actual security why not have a spec for /humans.txt which can say things like "Please don't read anything in the /secret directory."
- gruez 8y agoand what would that achieve? all it's going to do is force companies to add legal boilerplate (eg. those "this message is intended for the recipient only..." that you see in email signatures) to every imaginable place to cover their ass, meanwhile doing nothing to improve security.
- FundThrowaway 8y agoTalk about no sense of humour.
- outworlder 8y agoAs if the brilliant minds behind this website would even know what a RFC is.
- fouc 8y agoThe RFC would be more for future "legal" defense around this type of issue to use as evidence for support of enumerable urls = public api.