W3C home > Mailing lists > Public > public-webappsec@w3.org > January 2014

Re: (nonce | hash)

From: Mike West <mkwst@google.com>
Date: Wed, 29 Jan 2014 15:23:42 -0800
Message-ID: <CAKXHy=c4T3k6aGg+yuAW-tfHp0p41cgNx9DzdWwtZ6X1wDyFBQ@mail.gmail.com>
To: Neil Matatall <neilm@twitter.com>
Cc: public-webappsec@w3.org
I thought we'd implicitly agreed to include both. I'd explicitly vote for
that: the use cases seem distinct and useful.

We have implementations for both in Blink, and haven't seen significant
overhead there.

On Jan 29, 2014 3:14 PM, "Neil Matatall" <neilm@twitter.com> wrote:

> Hello,
> In a recent conversation I was reminded that the inclusion of either
> or both is still up in the air. What can we do to make this decision
> happen?
> I fully support both options in their own right and I think having
> both options is good in the short and long term. But I'm also not the
> one writing the code or spec to support this :)
> Today's call would have been a good time to bring this up. I'd love to
> start addressing concerns sooner than later. If only on the next call.
Received on Wednesday, 29 January 2014 23:24:11 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:37 UTC