Monday, 29 September 2014
Sunday, 28 September 2014
Saturday, 27 September 2014
- Re: Feature-detecting a Content Security Policy
- Re: Feature-detecting a Content Security Policy
- Re: Redirects and HSTS
Friday, 26 September 2014
Saturday, 27 September 2014
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
Friday, 26 September 2014
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- [webappsec] Changing my organizational hats
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Proposal: Prefer secure origins for powerful new web platform features
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Re: Redirects and HSTS
- Redirects and HSTS
- Re: Proposal: Prefer secure origins for powerful new web platform features
Thursday, 25 September 2014
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
Wednesday, 24 September 2014
- Re: Subresource integrity in Chromium
- Re: Subresource integrity in Chromium
- Re: Subresource integrity in Chromium
- Re: Verified Javascript for WebAppSec re-chartering?
- Re: Subresource integrity in Chromium
- Looking for a home for a proposed Credential Management API.
- Fwd: Verified Javascript for WebAppSec re-chartering?
- [webappsec] tomorrow's call CANCELLED
- Re: Subresource integrity in Chromium
Tuesday, 23 September 2014
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
- Subresource integrity in Chromium
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
Monday, 22 September 2014
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
- Re: [Integrity] Some comments on Cross-Origin leakage and content types
Sunday, 21 September 2014
Saturday, 20 September 2014
- [Integrity] Some comments on Cross-Origin leakage and content types
- Re: Proposal: not-a-scheme digest URI scheme, with graceful degradation
- Re: Proposal: not-a-scheme digest URI scheme, with graceful degradation
- Re: Proposal: not-a-scheme digest URI scheme, with graceful degradation
- Re: Proposal: not-a-scheme digest URI scheme, with graceful degradation
- Proposal: not-a-scheme digest URI scheme, with graceful degradation
Wednesday, 17 September 2014
- [webappsec] Re-chartering discussions at TPAC
- Re: [MIX] Feedback on the private origin & self-signed certificate requirements
- RE: [MIX] Feedback on the private origin & self-signed certificate requirements
- RE: [MIX] Feedback on the private origin & self-signed certificate requirements
Tuesday, 16 September 2014
- Review request for a few WebAppSec specs.
- Re: [MIX] Feedback on the private origin & self-signed certificate requirements
- Re: [MIX] Feedback on the private origin & self-signed certificate requirements
- [Integrity] hash in HTTP header field
- Re: CSP reports on eval() and inline
Monday, 15 September 2014
- [Integrity] Some comments on Subresource Integrity draft
- [webappsec] Poll: new teleconference time
- Re: CSP: Minimum cipher strength
- Re: [MIX] Feedback on the private origin & self-signed certificate requirements
- Re: CSP: Minimum cipher strength
Sunday, 14 September 2014
Monday, 15 September 2014
- RE: [MIX] Feedback on the private origin & self-signed certificate requirements
- Re: CSP: Minimum cipher strength
Sunday, 14 September 2014
- Re: CSP: Minimum cipher strength
- Re: [MIX] Feedback on the private origin & self-signed certificate requirements
- Re: CSP: Minimum cipher strength
Saturday, 13 September 2014
Friday, 12 September 2014
- Re: [CSP] compatibility between CSP1.1 and CSP2
- [CSP] compatibility between CSP1.1 and CSP2
- Review request for a few WebAppSec specs.
Thursday, 11 September 2014
- Re: HTML Imports vs unsafe-inline
- Re: HTML Imports vs unsafe-inline
- Re: HTML Imports vs unsafe-inline
- HTML Imports vs unsafe-inline
Wednesday, 10 September 2014
- Re: CSP: Minimum cipher strength
- RE: CfC: Publish a new WD of MIX.
- Re: CfC: Publish a new WD of MIX.
- Re: CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
Tuesday, 9 September 2014
- [webappsec] Agenda: WebAppSec WG Teleconference 10-September-2014 08:00 PDT
- Re: CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
Monday, 8 September 2014
- Re: CSP: Minimum cipher strength
- Re: CSP: Minimum cipher strength
- CSP: Minimum cipher strength
- [CSP] why we do it!
Saturday, 6 September 2014
Friday, 5 September 2014
- Re: CSP reports on eval() and inline
- Re: XMLHttpRequest. Support for "OPTIONS *" method.
- Re: XMLHttpRequest. Support for "OPTIONS *" method.
- Re: XMLHttpRequest. Support for "OPTIONS *" method.
- Re: XMLHttpRequest. Support for "OPTIONS *" method.
- Re: XMLHttpRequest. Support for "OPTIONS *" method.
Thursday, 4 September 2014
- Re: SRI: <a> vs integrity
- Re: CSP reports on eval() and inline
- Re: CSP reports on eval() and inline
- Re: CSP reports on eval() and inline
- Re: CSP reports on eval() and inline
- Re: CSP reports on eval() and inline
- RE: CSP reports on eval() and inline
- Re: CSP reports on eval() and inline
Wednesday, 3 September 2014
- CSP reports on eval() and inline
- Re: CSP Level 2 last call comment
- CfC: Publish a new WD of MIX.
- Re: [webappsec] Concluding the Last Call period for CSP Level 2
- Re: CSP for WebRTC
- webappsec-ISSUE-67: WebRTC via 'connect-src'?
- Re: CSP Level 2 last call comment
- Re: CSP Level 2 last call comment
- Re: [CSP] Regarding style-src unsafe-eval and CSSOM
- Re: CSP Level 2 last call comment
- Re: Defining secure-enough origins.
Tuesday, 2 September 2014
- Re: Defining secure-enough origins.
- Re: Defining secure-enough origins.
- Re: CSP Level 2 last call comment
- Re: CSP Level 2 last call comment
- Re: CSP for WebRTC
Monday, 1 September 2014
- Re: CSP Level 2 last call comment
- Re: [webappsec] Concluding the Last Call period for CSP Level 2
- Re: [CSP] Compatibility with 1.1 or 1.0
- Re: [CSP] kill or delay child-src?
- Re: CSP Level 2 last call comment
- Re: ISSUE-65: Does "no referrer" specify a state or is it a token? is a token with a space problematic?
- Re: [CSP] may we have script-ancestors to protect JSONP call
- Re: [CSP] kill or delay child-src?
- Re: CSP for WebRTC
- Re: [CSP] Regarding style-src unsafe-eval and CSSOM