W3C home > Mailing lists > Public > public-webappsec@w3.org > May 2015

Re: [SRI] Comments on Subresource Integrity spec

From: Gervase Markham <gerv@mozilla.org>
Date: Mon, 18 May 2015 14:16:41 +0100
To: Devdatta Akhawe <dev.akhawe@gmail.com>, Joel Weinberger <jww@chromium.org>
Cc: "public-webappsec@w3.org" <public-webappsec@w3.org>
Message-ID: <5559E639.70206@mozilla.org>
On 17/05/15 08:51, Devdatta Akhawe wrote:
> "User agents MAY deprecate support (by blocking loads) for integrity
> validation using hash functions deemed insecure. Web application authors
> SHOULD update integrity metadata to remove use of insecure hash functions."

No problem with the second sentence. The first seems fairly specific; I
thought you were arguing for flexibility in how UAs handle "deprecation"?

Received on Monday, 18 May 2015 13:17:12 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:49 UTC