Re: [whatwg/fetch] Update Fetch to support Token Binding. (#325)

I like Ryan's way of distinguishing the two dimensions.

> On the 3P/1P dimension, I think we can agree that a TB is potentially-identifying, and should be omitted, the same as cookies are.
Yes.

> Whether that also means that a new connection (non-TB-negotiated) should be established is unclear to me.
TB negotiation in the TLS handshake does not identify the client. TB messages (sent in HTTP headers) can identify the client.


-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/pull/325#issuecomment-377054089

Received on Wednesday, 28 March 2018 22:08:58 UTC