Re: [w3ctag/design-reviews] Early Design Review for Device Bound Session Credentials (Issue #1052)

martinthomson left a comment (w3ctag/design-reviews#1052)

Hi @drubery, we've taken a look at your design and think that the basic approach here is worthwhile, but the integration with cookies could be more natural than it is in your design.

We've [a much longer analysis](https://github.com/w3ctag/design-reviews/blob/main/reviews/dbsc-analysis.md) that describes an alternative approach that we think you should take a look at.  That document describes what we understand the goals to be and a different way of addressing them.  Credit to @jricher for the idea of using HTTP message signatures there.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/1052#issuecomment-2946681508
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/1052/2946681508@github.com>

Received on Thursday, 5 June 2025 22:44:55 UTC