Re: Registration of media typeimage/svg+xml

Chris Lilley <chris@w3.org> Thu, 18 November 2010 22:24 UTC

Received: from hoffman.proper.com (localhost [127.0.0.1]) by hoffman.proper.com (8.14.4/8.14.3) with ESMTP id oAIMOOoK091449 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 18 Nov 2010 15:24:24 -0700 (MST) (envelope-from owner-ietf-xml-mime@mail.imc.org)
Received: (from majordom@localhost) by hoffman.proper.com (8.14.4/8.13.5/Submit) id oAIMOOJ3091448; Thu, 18 Nov 2010 15:24:24 -0700 (MST) (envelope-from owner-ietf-xml-mime@mail.imc.org)
X-Authentication-Warning: hoffman.proper.com: majordom set sender to owner-ietf-xml-mime@mail.imc.org using -f
Received: from jay.w3.org (ssh.w3.org [128.30.52.60]) by hoffman.proper.com (8.14.4/8.14.3) with ESMTP id oAIMON00091443 (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO) for <ietf-xml-mime@imc.org>; Thu, 18 Nov 2010 15:24:23 -0700 (MST) (envelope-from chris@w3.org)
Received: from localhost ([127.0.0.1]) by jay.w3.org with esmtpa (Exim 4.69) (envelope-from <chris@w3.org>) id 1PJCtk-0001ii-Cv; Thu, 18 Nov 2010 17:24:08 -0500
Date: Thu, 18 Nov 2010 23:22:49 +0100
From: Chris Lilley <chris@w3.org>
X-Mailer: The Bat! (v3.95.6) Home
Reply-To: Chris Lilley <chris@w3.org>
Organization: W3C
X-Priority: 3 (Normal)
Message-ID: <784237972.20101118232249@w3.org>
To: Ned Freed <ned.freed@mrochek.com>
CC: Julian Reschke <julian.reschke@gmx.de>, ietf-types@iana.org, <ietf-xml-mime@imc.org>, Alexey Melnikov <alexey.melnikov@isode.com>
Subject: Re: Registration of media typeimage/svg+xml
In-Reply-To: <01NUEK09JNWC007FL5@mauve.mrochek.com>
References: <1364503167.20100617162624@w3.org> <1715145489.20101118190255@w3.org> <4CE57C38.4080307@gmx.de> <282747763.20101118210121@w3.org> <4CE58A74.2060503@gmx.de> <01NUEK09JNWC007FL5@mauve.mrochek.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-xml-mime@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-xml-mime/mail-archive/>
List-ID: <ietf-xml-mime.imc.org>
List-Unsubscribe: <mailto:ietf-xml-mime-request@imc.org?body=unsubscribe>

On Thursday, November 18, 2010, 10:26:51 PM, Ned wrote:

>> On 18.11.2010 21:01, Chris Lilley wrote:
 read BCP 13, RFC 4288 section 4.6 "Security requirements" where you will find
>> >
>> >        A media type that employs compression may provide an opportunity
>> >        for sending a small amount of data that, when received and
>> >        evaluated, expands enormously to consume all of the recipient's
>> >        resources.  All media types SHOULD state whether or not they
>> >        employ compression, and if they do they should discuss
>> >        what  steps need to be taken to avoid such attacks.

NF> Read the section again. It is clearly talking about media types that employ
NF> compression *internally*, not compression done at other layers.

NF> Any media type can, and often is, compressed at other layers. Discussion
NF> of such actions has no business being in any particular media type
NF> registration.

OK. 

NF> If, however, the answer is never - and I'm pretty sure it is - then all mention
NF> of compression needs to be dropped from this registration, as it is doing
NF> nothing useful and is just making things unclear. At most you might want a note
NF> about it in the encoding consideration sections saying external compression is
NF> often used with this type. Again, lots of media types are compressed at other
NF> layers; this has nothing to do with the image/svg+xml media type specifically.

In that case I can remove the section.

Julian, does that satisfy your concern as well?


-- 
 Chris Lilley   Technical Director, Interaction Domain                 
 W3C Graphics Activity Lead, Fonts Activity Lead
 Co-Chair, W3C Hypertext CG
 Member, CSS, WebFonts, SVG Working Groups