"Unfortunately, not all of these headers are supported in all browsers, meaning any of you still using IE6 won’t be able to take advantage of these headers."
That would be a plausible explanation for the fact that they use a user-agent based whitelisting. If one's protections rely on client-side features, it's a bit more understandable (though I still find it a bit weak) to try to enforce use of a browser that implements them.
That would be a plausible explanation for the fact that they use a user-agent based whitelisting. If one's protections rely on client-side features, it's a bit more understandable (though I still find it a bit weak) to try to enforce use of a browser that implements them.