Re: [Tech] Opera JPEG vulnerability

Top Page
Author: Matthew Toseland
Date:  
To: tech
Subject: Re: [Tech] Opera JPEG vulnerability
Delete this message
Reply to this message
gpg: Signature made Fri Feb 29 18:53:48 2008 UTC using DSA key ID E43DA450
gpg: Good signature from "Matthew John Toseland <toad@amphibian.dyndns.org>"
On Friday 29 February 2008 18:49, Marco A. Calamari wrote:
> On Wed, 2008-02-27 at 18:51 +0000, Matthew Toseland wrote:
> > This is interesting because it came at the end of a thread on Frost where

the
> > OP was arguing that Freenet shouldn't filter JPEGs. (Freenet strips out

EXIF
> > data and other unknown chunks from JPEGs on download to maximize security;

in
> > the future we will do something similar on inserts).
>
> IMHO changing in any way information inserted in Freenet *must*
> be documented, evident in user interface, up by default
> but easily user selectable.


The intention is that there should be a checkbox in jSite etc to turn
insert-time filtering on or off. Maybe a global one and a per-file one too.