[trojita] Re: User Agent Info Leak

2015-03-03 Thread Jason A. Donenfeld
On Tue, Mar 3, 2015 at 1:10 PM, Jan Kundrát wrote: > > I'm not saying "nope", but I wonder why you're asking for this. The > User-Agent comes handy when troubleshooting various interoperability issues; It also comes in handy for forming targeted attacks against MUAs with zero-day vulnerabilities

Re: [trojita] User Agent Info Leak

2015-03-03 Thread Jason A. Donenfeld
On Tue, Mar 3, 2015 at 1:40 PM, Jan Kundrát wrote: > > Now, maybe we could change the pref to switch between "identify Trojita > including the Qt version" and "just say it's Trojita". Am I right that this > won't be a correct fix from your point of view, and that you absolutely > want to have noth

Re: [trojita] User Agent Info Leak

2015-03-03 Thread Jason A. Donenfeld
It's not security by obscurity. It's a first step in combating fingerprinting, and removing an info leak. CWE-200