No, we should have a warning because the algorithm is unknown and the tests are not exhaustive.
Fair enough. This is an implementation of the same origin policy, yes? Wikipedia provides some interesting examples, for instance, having different port numbers in the same domain can cause a mismatch: http://en.wikipedia.org/wiki/Same_origin_policy --Juan