[TYPO3] Removing the meta "generator" from header
Claudio Strizzolo
claudio.strizzolo at ts.nogarb.ageinfn.it
Wed Dec 5 09:08:00 CET 2007
> so use proper name for TYPO3, please.
I apologize.
> Well, even if you remove it, it is very easy to say that it is TYPO3
> just by looking at html.
I know this, and I agree with you: it is absolutely reasonable that the
pages report that they have been built through TYPO3.
As you may see, I did not complain about this, and agree with the fact
that the header of the pages includes, for instance, the following note:
<!--
This website is powered by TYPO3 - inspiring people to share!
(...)
This is good.
> and you are expect to have some respect to the system.
It is not my will not to have respect for TYPO3, which is a software I
use and like a lot. I'm sorry if I gave this impression to you.
What I don't like, and would like to avoid, is to show the VERSION of
TYPO3 through which the pages were built, basically for security reasons:
imagine that I have used a version of TYPO3 that later is discovered to
be buggy about security, and I haven't had time to update yet. If the
code of the pages shows the version of the software, this could be an
hint for malicious people trying to force my system: they might be aware
that my web server is using a buggy software and trying to break it.
Up to now, TYPO3 has looked solid as a rock to me, but who knows what
might happen in the future? Bugs happen.
For instance, I find absolutely reasonable that the administrative login
page (http://mysite.org/typo3/) does not display the version of TYPO3 in
use, for the very same reason.
Best regards
Claudio
More information about the TYPO3-english
mailing list