Re: postMessage, workers and sandboxing
Re: CSP3: DOM API Strawman
[CSP] CSP3: Request for comments on message-src and message-sink
Security use cases for packaging
- Re: Security use cases for packaging
POWER: Combining document and settings object checks.
- Re: POWER: Combining document and settings object checks.
- Re: POWER: Combining document and settings object checks.
[SRI] Suggesting Francois Marier (Mozilla) as editor
- Re: [SRI] Suggesting Francois Marier (Mozilla) as editor
- Re: [SRI] Suggesting Francois Marier (Mozilla) as editor
CSP unsafe-eval alternative for a 'trusted' or 'eval-src: self'?
CfC: Transition CSP2 to CR.
[MIX] HSTS, SW and mixed-content
Service workers and CSP
[SRI] format of the integrity attribute
- Re: [SRI] format of the integrity attribute
Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
- Re: Proposal: A pinning mechanism for CSP?
Cancelling next week's call?
Re: [CSP] Clarifications on nonces
Re: [CSP] Dynamic CSP
CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
- Re: CSP: Drop IP-matching? (was Re: [CSP] URI/IRI normalization and comparison)
CREDENTIAL: And now for something completely different...
[CSP2] Browser Support
[CSP2] Browser Support
CSP Versions in Violation Reports
[SRI] Reserving the "authority" component of NI URIs for later use?
[CSP] Accepting base64-url
Re: [CSP] Clarifications regarding the HTTP LINK Header
Plugin data (was Re: Comments on Mixed Content)
Re: Strict mixed content checking (was Re: MIX: Exiting last call?)
- Re: Strict mixed content checking (was Re: MIX: Exiting last call?)
- Re: Strict mixed content checking (was Re: MIX: Exiting last call?)
- Re: Strict mixed content checking (was Re: MIX: Exiting last call?)
Re: [CSP] URI/IRI normalization and comparison
- Re: [CSP] URI/IRI normalization and comparison
Re: [CSP] Problems with frame-ancestors; X-Frame-Options not obsolete?
Re: [CSP] <meta> clarifications
Re: [CSP] violation reports for sandbox
Re: [CSP] Relative/absolute hostname matching
Re: [MIX] PF comments on Mixed Content - accessible indication and user controls
RE: Comments on Mixed Content
webappsec-ACTION-211: Ask github if they prefer fail open / closed on unknown hashes
webappsec-ACTION-210: Move sri bugs in bugzilla to github
webappsec-ACTION-209: Ask open data/linked data groups for info on data publishing for use in secure context
[webappsec] Teleconference Agenda, 12-Jan-2015 12:00 PST
[CORS] Implementation Report links in CORS REC return errors
[CSP] Geotargetting?
Re: Avoiding syncronous manifest requests in EPR
Accessibility of security indicators
Re: Comments on Mixed Content
Re: [CSP] How to interpret 'self' in a sandboxed iframe
- Re: [CSP] How to interpret 'self' in a sandboxed iframe
- Re: [CSP] How to interpret 'self' in a sandboxed iframe
Re: [SRI] providing good defaults when the expected content type is missing?
Re: [CSP3] Allow paths without a domain
Re: [CSP3] Allow plugin-types "none"
Re: [REFERRER] Combination of referrer directive values
Adding window.opener control to referrer-policy?
[SRI] Include sha-384 in the spec?
[Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
- Re: [Integrity] typos with ni URIs
[Bug 27748] New: Value of @integrity attribute not sufficiently prescriptive
[Bug 27747] New: Integrity of font content
[Bug 27746] New: Integrity of image content
[Bug 27745] New: Should define the term 'integrity'
[Bug 27744] New: Should define the term 'subresource'
[SRI] Getting sha-384 and sha-512 added to the RFC6920 registry?
Re: [SRI] unsupported hashes and invalid metadata
Re: [blink-dev] Re: Proposal: Marking HTTP As Non-Secure
- Re: [blink-dev] Re: Proposal: Marking HTTP As Non-Secure
[MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- optimistic HTTP → HTTPS [was: Re: Require HTTPS scripts to be able to anything HTTP scripts can do.]
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.
- Re: [MIX] Require HTTPS scripts to be able to anything HTTP scripts can do.