Re: [w3ctag/design-reviews] Scheme-bound Cookies (#483)

@jwrosewell there's pretty broad support in the web/internet community to move to secure transports. Prior art here are TLS, HTTPS, HTTP/2 onward being restricted to TLS, secure contexts, mixed content blocking, Referer header degradation, etc. What are the concrete reasons to not align cookies with that security boundary?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/483#issuecomment-615897809

Received on Saturday, 18 April 2020 16:20:31 UTC