[opensource-dev] Request for comments about llSetAgentEnvironment / SVC-5520
Argent Stonecutter
secret.argent at gmail.com
Fri Mar 12 08:28:52 PST 2010
On 2010-03-12, at 09:58, Dickson, Mike (ISS Software) wrote:
> That's not what it does.
>
> Streaming media (and media on a prim) is enabled on by default as
> opposed to the old viewer where it was off and needed to be
> explicitly enabled. There are pros and cons to either approach of
> course. And it is a beta. This is an area I'm sure LL would
> appreciate some feedback since it's a new feature/extension of an
> existing one.
Oh, that's a lot less dire. Thank you.
I still think that
* Streaming media and media on a prim should be OFF by default.
* When enabled, there should be a warning that this may expose you to
privacy and security exploits.
I don't think that the SL client should be considered as secure and
reliable an environment as a web browser: it's much larger and more
complex and there have been indirect attacks on the viewer (eg, map-
bombing) even though the SL servers act as a fairly good application
level proxy firewall between users. People shouldn't be accessing
potentially untrusted URLs from the client without explicit action.
More information about the opensource-dev
mailing list