> Two and three are not really solutions, they are simply bikeshedding.

That's not what "bikeshedding" means. You just don't like those solutions
personally, but they are solutions and will, eventually, be what everyone
does. Microsoft is a lot better at upgrading people with Windows 7 and up
than they were with XP.

> Two can increase attack surface, and even violate policy. For example,
> a corporate policy may prohibit installing non essential software like
> the Firefox browser on a Windows server. For those who don't violate
> policy, they have an increased attack surface.

That doesn't have any bearing on whether WebCrypto is achieving its goals,
or likely to become a standard. This is normal.

> The shim looks promising. But what's the point if WebCrypto is
> supposed to standardize these things? Why not forgo all the WebCrypto
> working group gyrations and skip to the shim?

This thread is pretty baffling. You may not prefer Windows 8/10 over 7, but
that's where Microsoft's going, and deprecating older browsers/OSes is how
things happen. Edge implemented WebCrypto, and MS isn't investing in old
browsers like IE11.

Many successful standards have gone through a "shim phase" as browsers
implement things at different paces. There's nothing out of the ordinary

Received on Sunday, 11 October 2015 22:29:36 UTC