So yeah, um, this is not okay. It is not discoverable and could easily leak sensitive information. Auth credentials even, seriously? Also Chrome does this too. And it is preserved across `mv` to another filesystem.https://twitter.com/gynvael/status/1077671412847046657 …
I'm sorry, when did we go from "logged in your browser history" to "public"? Your argument is bullshit. You're saying that just because a particular thing has some (known) security caveats it's fine to gratuitously introduce more undiscoverable ones to bite people in the ass.
-
-
Sorry, but ultimately it comes down to this: curl is following the RFCs, and you are not.
-
Sometimes the RFCs are bullshit. If people followed the RFCs to the letter anyone could DoS any server, because they require vulnerable implementations of things like TCP. This is one of those times.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
$ getfattr -d -m - test
user.xdg.origin.url="https://user:passwd@gynvael.coldwind.pl/"