W3C home > Mailing lists > Public > public-webappsec@w3.org > February 2015

Re: UPGRADE: Goals? (was Re: CfC to publish FPWD of "Upgrade Insecure Resources"; Deadline Feb 17th.)

From: Brad Hill <hillbrad@gmail.com>
Date: Wed, 11 Feb 2015 18:24:21 +0000
Message-ID: <CAEeYn8jB2rA4SePLijrfWBsY_irzo_Cm+azxSYRivKbweOODdA@mail.gmail.com>
To: Mike West <mkwst@google.com>
Cc: Jim Manico <jim.manico@owasp.org>, Crispin Cowan <crispin@microsoft.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>, Dan Veditz <dveditz@mozilla.com>, Wendy Seltzer <wseltzer@w3.org>, Peter Eckersley <pde@eff.org>, yan zhu <yan@mit.edu>
Thanks, Mike, that looks good.   Should we promote the following note (or
new language to indicate the same) from section 4.1 to the
goals/introduction?

Note: We allow only same-origin upgrades in order to ensure that
navigations between pages of a single site that has opted-into the upgrade
behavior remain on HTTPS, regardless of the hard-coded values in <a> tags.
Performing upgrades for third-party resources brings a significantly higher
potential for breakage, so we’re avoiding it for the moment.


On Wed Feb 11 2015 at 6:04:39 AM Mike West <mkwst@google.com> wrote:

> Forking this thread for clarity.
>
> On Tue, Feb 10, 2015 at 8:07 PM, Brad Hill <hillbrad@gmail.com> wrote:
> > I think this spec would be well-served to have an explicit "Goals"
> section
> > in the introduction describing exactly what can be accomplished and how
> it
> > compares feature-wise to HSTS.
>
> A good idea indeed. I've added
> https://w3c.github.io/webappsec/specs/upgrade/#goals to the document.
> WDYT?
>
> -mike
>
> --
> Mike West <mkwst@google.com>, @mikewest
>
> Google Germany GmbH, Dienerstrasse 12, 80331 München, Germany,
> Registergericht und -nummer: Hamburg, HRB 86891, Sitz der Gesellschaft:
> Hamburg, Geschäftsführer: Graham Law, Christine Elizabeth Flores
> (Sorry; I'm legally required to add this exciting detail to emails. Bleh.)
>
Received on Wednesday, 11 February 2015 18:24:49 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:10 UTC