- From: Trevor Perrin <trevp@trevp.net>
- Date: Fri, 13 Sep 2013 16:57:13 -0700
- To: "Nottingham, Mark" <mnotting@akamai.com>
- Cc: Tobias Gondrom <tobias.gondrom@gondrom.org>, "public-webappsec@w3.org" <public-webappsec@w3.org>
On Fri, Sep 13, 2013 at 4:47 PM, Nottingham, Mark <mnotting@akamai.com> wrote: > I don't see how CSP is competitive to those more ambitious approaches. They would (hopefully!) solve the problem your CSP proposal is trying to solve, but solve it in a broader way so cookies are protected whether they are read/written via Javascript *or* HTTP headers. Trevor
Received on Friday, 13 September 2013 23:57:40 UTC