Re: [websec] Resuming the cookie discussion

2013-08-20 Thread Yoav Nir
Hi Trevor. I think (a) is definitely worth doing, but I also think that (b) can be done along the way. Is there some reason why (a) and (b) can't be requirements filled by a single mechanism? Regarding smart cookies vs channel ID: Not changing TLS is a definite advantage of Smart Cookies. Rea

Re: [websec] Resuming the cookie discussion

2013-08-20 Thread Trevor Perrin
On Tue, Aug 20, 2013 at 1:39 AM, Yoav Nir wrote: > Hi Trevor. > > I think (a) is definitely worth doing, but I also think that (b) can be done > along the way. Interesting... If we were to prioritize them, I'd argue the reverse: (b) ("Origin Cookies") strikes me as the most economical, since it

Re: [websec] Resuming the cookie discussion

2013-08-20 Thread Yoav Nir
On Aug 20, 2013, at 9:01 PM, Trevor Perrin wrote: > On Tue, Aug 20, 2013 at 1:39 AM, Yoav Nir wrote: >> Hi Trevor. >> >> I think (a) is definitely worth doing, but I also think that (b) can be done >> along the way. > > Interesting... If we were to prioritize them, I'd argue the reverse: >