Dear Microsoft: Please Do Pinned Menus Like This
blog.theamazingrando.com
blog.theamazingrando.com
1) It's much easier to stick meta tags in HTML than it is to reference an external file in many cases (blog hosting services, hosted storefronts, etc).
2) Sites that make the best use of that menu will have different data depending on what page is pinned. We didn't do much implementation, but assuming enough people used IE9 we'd probably make that set of meta tags page dependent. Separating it into an external link when it's page specific data doesn't make a bunch of sense. Particularly page specific data that changes frequently.
Also, that 1kb of text is more like 260 bytes gzipped (as it is for us). We'll survive. :)
And even gzipped, 260B * 1M pageviews/day is ~ 1GB a month. Plus the memory to hold the text, the CPU to compress it, versus serving a static file from Apache to the fraction of users the ask for it? Still sounds like a win.
Maybe make it even more like stylesheets: embeddable in the page or linkable to another page.
Edit: Additionally, how does what's in the pinned menu get updated? Does it need to make a full page request to get the new items? This will needlessly inflate pageview numbers in that case (I'm sure the "fix" for that will be that Microsoft will change the User Agent to say that it's not the browser but rather than pinned menu making the request). As for implementation, does the browser create the menu from the this and it's static? Or does the URL to the page get passed to the menu bar where it is pinned and then the menu bar is responsible for making the request? Or does the browser actually run the menu bar -- this seems like the wrong kind of integration.
The main argument seems to be that the metadata involved here is to do with the site, not the page, whereas <meta> tags should be for resource-specific use.
If websites comes to support this, I'm pretty sure I will welcome that as a feature. Not required by any means, but a nice extra.
I really hope this appeal gains some traction. Pinning and jump-lists should be seen as Windows 7 features, not IE9 features (which runs on Vista too).
It'd be much better if MS were to just take a page outline (from all the headlines) that were links and make their menu out of that. Or, look at the HTML5 <nav> elements. Then IE9 users might actually see it in use once in a blue moon.
It's still worth investigating doing it right, instead of letting IE define the standard, and letting it stagnate.
Why would the existence of this feature lead to a remote compromise? The specific implementation maybe, but the idea??
The idea of a website being able to inject things into the task bar menu seems like it would open the door for injecting things that overflow buffers, call other code, etc. What is the security model for that code? What are the limits on what the URL can point to, etc.
It's not like the IE team has a stellar record for this kind of stuff?
All of those risks are present for PDFs or png images. If the browser's XML parser is vulnerable, having this feature additionally available won't make and difference.
That's a pretty short time span for the definition of "always".