Expect-CT updates

I won't be able to make it to Singapore, so here are a few updates on
Expect-CT:

- In Prague we talked about CORS preflights for reporting requests.
https://github.com/whatwg/fetch/issues/567 is the resulting discussion,
though it hasn't really had a satisfying resolution yet.
https://github.com/whatwg/fetch/pull/621 documents some CORS exceptions,
including Expect-CT reports.

- Expect-CT is now shipped in Chrome stable and several large sites have
deployed the header. One large site has requested includeSubdomains support
and doesn't want to deploy Expect-CT without it.

- Ivan Ristic (Hardenize) is planning on filing a few small spec issues
(mostly related to the report format, IIUC) this week or next based on his
deployment experience.

Received on Friday, 10 November 2017 16:39:27 UTC