W3C home > Mailing lists > Public > public-webappsec@w3.org > February 2015

Re: UPGRADE: Goals? (was Re: CfC to publish FPWD of "Upgrade Insecure Resources"; Deadline Feb 17th.)

From: Mike West <mkwst@google.com>
Date: Thu, 12 Feb 2015 07:46:18 +0100
Message-ID: <CAKXHy=f5bo9bNi=jT45vNk+AFCh7iht0g_Ezb-Jt=ZQfzsJK-g@mail.gmail.com>
To: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
Cc: Brad Hill <hillbrad@gmail.com>, Jim Manico <jim.manico@owasp.org>, Crispin Cowan <crispin@microsoft.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>, Dan Veditz <dveditz@mozilla.com>, Wendy Seltzer <wseltzer@w3.org>, Peter Eckersley <pde@eff.org>, yan zhu <yan@mit.edu>
On Wed, Feb 11, 2015 at 8:33 PM, Daniel Kahn Gillmor
<dkg@fifthhorseman.net> wrote:
> On Wed 2015-02-11 13:24:21 -0500, Brad Hill wrote:
>> Thanks, Mike, that looks good.   Should we promote the following note (or
>> new language to indicate the same) from section 4.1 to the
>> goals/introduction?

I intended goal #3 to cover this: "Authors should be able to ensure
that all inter-site links correctly send users to the site's secure
address, and not to it's pre-migration insecure address."

Is that enough, or would you like to see it changed in some way?

> This note is intended to be limited to navigation upgrades, right?
> In that case, the last sentense should begin with something like:
>  Performing upgrades for navigations to third-party resources...
>                          ^^^^^^^^^^^^^^

Sure. Done in https://github.com/w3c/webappsec/commit/248456d12f835197b83b62656aadbd4c2e7c9b42.


Mike West <mkwst@google.com>, @mikewest

Google Germany GmbH, Dienerstrasse 12, 80331 München, Germany,
Registergericht und -nummer: Hamburg, HRB 86891, Sitz der
Gesellschaft: Hamburg, Geschäftsführer: Graham Law, Christine
Elizabeth Flores
(Sorry; I'm legally required to add this exciting detail to emails. Bleh.)
Received on Thursday, 12 February 2015 06:47:06 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:46 UTC