Re: revised "generic syntax" and "data:" internet drafts

Chris Newman <Chris.Newman@innosoft.com> Thu, 03 April 1997 01:31 UTC

Received: from cnri by ietf.org id aa08097; 2 Apr 97 20:31 EST
Received: from services.Bunyip.Com by CNRI.Reston.VA.US id aa23522; 2 Apr 97 20:31 EST
Received: (from daemon@localhost) by services.bunyip.com (8.8.5/8.8.5) id UAA05980 for uri-out; Wed, 2 Apr 1997 20:13:54 -0500 (EST)
Received: from mocha.bunyip.com (mocha.Bunyip.Com [192.197.208.1]) by services.bunyip.com (8.8.5/8.8.5) with SMTP id UAA05963 for <uri@services.bunyip.com>; Wed, 2 Apr 1997 20:13:51 -0500 (EST)
Received: from THOR.INNOSOFT.COM by mocha.bunyip.com with SMTP (5.65a/IDA-1.4.2b/CC-Guru-2b) id AA04731 (mail destined for uri@services.bunyip.com); Wed, 2 Apr 97 20:13:50 -0500
Received: from eleanor.innosoft.com by INNOSOFT.COM (PMDF V5.1-8 #8694) with SMTP id <01IH8KDNMJQG8WX0F5@INNOSOFT.COM> for uri@bunyip.com; Wed, 2 Apr 1997 17:12:42 PST
Date: Wed, 02 Apr 1997 17:14:01 -0800
From: Chris Newman <Chris.Newman@innosoft.com>
Subject: Re: revised "generic syntax" and "data:" internet drafts
In-Reply-To: <3342F153.27B1@parc.xerox.com>
To: Larry Masinter <masinter@parc.xerox.com>
Cc: IETF URI list <uri@bunyip.com>, ietf-url@imc.org
Message-Id: <Pine.SOL.3.95.970402171120.2607A-100000@eleanor.innosoft.com>
Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Sender: owner-uri@bunyip.com
Precedence: bulk

On Wed, 2 Apr 1997, Larry Masinter wrote:

> > >   ftp://ftp.ietf.org/internet-drafts/draft-fielding-url-syntax-04.txt
> > Section 2.1.3 largely duplicates section 2.5.
> > Section 2.2.2 has a "of of"
> > I think the process in section 3 is unworkable. 
> 
> I think you were looking at a different document, since there is no section
> 2.1.3, 2.2.2, and section 3 is not about process. (All of the process stuff
> was removed).

Those comments were referring to the process document.

> > I think the ":<password>" should be removed from the default Internet
> > component.  Otherwise you encourage plaintext passwords (people will use
> > them anyway if really necessary).
> 
> This isn't the "default" Internet component, it is the "generic" Internet
> component. And the security considerations section says:
> 
>    It is clearly unwise to use a URL that contains a password which is
>    intended to be secret.
> 
> Need it say more?

No.  It needs to say less.  Don't even bother suggesting a syntax for
cleartext passwords -- it's not useful in the "generic" case.