The JSON reference really needs to be to RFC 7159, not 4627. (blocking, but 
trivial issue)

There should be some mention of the prior art in this space.  Pingbacks and 
trackbacks at least.  Please differentiate this approach from them, so we have 
an idea if we need to do this also.  Many Wordpress sites get nuked pretty 
quickly when they leave pingbacks on; pointing out the linkage is important so 
that the industry at least learns from some of the attacks that have worked in 
the past.

Section 4.5 "Limit access to protected resources" points out that this protocol 
is an attractive nuisance.  Anyone who deploys it is likely to make their 
infrastructure more insecure by mistake.  

If there's a good reason to publish this that isn't obvious, I might be more 
excited about it.


> On Nov 3, 2016, at 7:25 PM, L. David Baron <dba...@dbaron.org> wrote:
> 
> A W3C Proposed Recommendation is available for the membership of W3C
> (including Mozilla) to vote on, before it proceeds to the final
> stage of being a W3C Recomendation:
> 
>  Webmention
>  W3C TR draft: https://www.w3.org/TR/webmention/
>  W3C Editor's draft: https://webmention.net/draft/
>  deadline: Wednesday, November 30 (23:59 in UTC-05:00)
> 
> If there are comments you think Mozilla should send as part of the
> review, please say so in this thread.  (I'd note, however, that
> there have been many previous opportunities to make comments, so
> it's somewhat bad form to bring up fundamental issues for the first
> time at this stage.)
> 
> -David
> 
> -- 
> 𝄞   L. David Baron                         http://dbaron.org/   𝄂
> 𝄢   Mozilla                          https://www.mozilla.org/   𝄂
>             Before I built a wall I'd ask to know
>             What I was walling in or walling out,
>             And to whom I was like to give offense.
>               - Robert Frost, Mending Wall (1914)
> _______________________________________________
> dev-platform mailing list
> dev-platform@lists.mozilla.org
> https://lists.mozilla.org/listinfo/dev-platform

-- 
Joe Hildebrand

_______________________________________________
dev-platform mailing list
dev-platform@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-platform

Reply via email to