[opensource-dev] Request for comments about llSetAgentEnvironment / SVC-5520

Argent Stonecutter secret.argent at gmail.com
Fri Mar 12 08:28:52 PST 2010


On 2010-03-12, at 09:58, Dickson, Mike (ISS Software) wrote:
> That's not what it does.
>
> Streaming media (and media on a prim) is enabled on by default as  
> opposed to the old viewer where it was off and needed to be  
> explicitly enabled.  There are pros and cons to either approach of  
> course. And it is a beta. This is an area I'm sure LL would  
> appreciate some feedback since it's a new feature/extension of an  
> existing one.

Oh, that's a lot less dire. Thank you.

I still think that

* Streaming media and media on a prim should be OFF by default.
* When enabled, there should be a warning that this may expose you to  
privacy and security exploits.

I don't think that the SL client should be considered as secure and  
reliable an environment as a web browser: it's much larger and more  
complex and there have been indirect attacks on the viewer (eg, map- 
bombing) even though the SL servers act as a fairly good application  
level proxy firewall between users. People shouldn't be accessing  
potentially untrusted URLs from the client without explicit action.


More information about the opensource-dev mailing list