Re: [whatwg/fetch] Clarification on CORS preflight fetches for TLS client certificates (#869)

thw0rted left a comment (whatwg/fetch#869)

> You are saying that as a service provider I am not entitled to that on the web?

I guess that's the question.  I mean, you as the service provider have an interest in ensuring that the client is really the end user; I as a business owner have an interest in saying that my employees can't have "true privacy" in network connections because I have a duty to make sure they aren't misusing proprietary information.  Those are competing interests and I don't think either side can claim absolute priority.

That said: is there a privacy guarantee provided by mTLS that can't also be provided by HSTS?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/869#issuecomment-4695758505
You are receiving this because you are subscribed to this thread.

Message ID: <whatwg/fetch/issues/869/4695758505@github.com>

Received on Friday, 12 June 2026 21:57:57 UTC