Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some browsers might try to sniff the mime type, so an additional header would help : "X-Content-Type-Options: nosniff"[1]

1. https://blogs.msdn.microsoft.com/ie/2008/09/02/ie8-security-...



Thanks! I remembered something like that existing but I couldn't remember the header name :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: