-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 3/26/12 6:22 AM, =JeffH wrote:
> [ this msg is a tad late, -06 was pub'd on 12-Mar, apologies.
> Sending it for the record. ]

Hi Jeff, thanks for addressing my earlier comments. I found time to
read -06 on the flight to Paris. Here are some small comments.

Section 1:

   This specification also incorporates notions from [JacksonBarth2008]
   in that policy is applied on an "entire-host" basis: it applies to
   all TCP ports of the issuing host.

Please make it clear that all TCP ports does not mean all application
protocols, only HTTP on all ports where it might be offered (not only
the ports registered with the IANA).

Section 7.2

Does is make sense to mention that status code 308 might be
appropriate in certain circumstances? See draft-reschke-http-status-308.

Section 8.4

The HTTP-Equiv <Meta> Element Attribute is defined in the HTML
specification, so a reference would be helpful.

Section 9

The phrase "valid Unicode-encoded string-serialized domain name" seems
a bit strange, because we don't typically refer to Unicode as an
encoding scheme. See RFC 6365 regarding such terminology.

Section 11.1

I think the text about "no user recourse" conflates two things:
showing a warning, and allowing the user to click through: "the user
should not be presented with an explanatory dialog giving her the
option to proceed." Would it be OK for a user agent to show an
explanatory dialog but not provide an option to proceed? Is there a
security reason to fail the connection without any explanation?

Section 11.5

The note it worded a bit oddly (e.g., "it shouldn't be possible for an
attacker to inject script..." might be better worded along the lines
of "implementations need to guard against alowing an attacker to
inject script...").

Peter

- --
Peter Saint-Andre
https://stpeter.im/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk9wDxUACgkQNL8k5A2w/vwzMwCg0eK+344UU3yBAuKuZS6G/YwQ
M48AoLfpwOK//yp/LbKWBS2Mn0D1++F4
=VgD6
-----END PGP SIGNATURE-----
_______________________________________________
websec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/websec

Reply via email to