On May 18, 2015, at 5:20 AM, Kepeng Li <kepeng.lkp@alibaba-inc.com <mailto:kepeng.lkp@alibaba-inc.com>> wrote: > >> 2. Privacy review request from Web Applications Security WG concerning >> Subresource Integrity [1] > > It seems that there are no privacy considerations in this document. > > Should we add something? There is a Security Considerations section that is likely relevant to the things we typically review: http://w3c.github.io/webappsec/specs/subresourceintegrity/#security-considerations-1 <http://w3c.github.io/webappsec/specs/subresourceintegrity/#security-considerations-1> For example, cross-origin data leakage is one of the considerations there. I wonder if authors should typically write these as "Security and Privacy Considerations" since they so often overlap. npdReceived on Tuesday, 19 May 2015 01:40:33 UTC
This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 16:49:29 UTC