public-webappsec@w3.org from November 2015 by subject

[mixed-content]

[SRI] editorial

[upgrade-insecure-requests]

[webappsec] Agenda for 15-Nov-2015 teleconference

[webappsec] Cancelled 12/30 call

[webappsec] new UISecurity draft for Monday

[webappsec] Poll for new meeting day

call for agenda items for Wednesday's conference call

Call for Exclusions (Update): Clear Site Data

Call for Exclusions: Subresource Integrity

CfC: CSP Cookie Controls to FPWD; deadline Dec. 7th.

CfC: CSP Embedded Enforcement to FPWD; deadline Dec. 7th.

High Resolution Time 2: time origin and worker support

HSTS Priming, continued.

In what circumstances is "delayed execution" acceptable on the web?

Marking HTTP As Non-Secure

Potential changes to cookies in Chrome.

Proposal: Showing the padlock icon on all secure origins

Proprietary dependencies (was Re: Request for review of the Presentation API from a security perspective)

referrer-policy attribute

Request for review of the Presentation API from a security perspective

Suborigin update

WS/Service Workers, TLS and future apps - [was Re: HTTP is just fine]

Last message date: Monday, 30 November 2015 23:16:21 UTC