Re: Intent to implement and ship: document.origin

2015-03-17 Thread Anne van Kesteren
On Wed, Mar 18, 2015 at 1:09 AM, Jonas Sicking wrote: > I think making the location object match URLUtils is futile. There's > so much weirdness about the location object that I think we should > treat it as the special flower that it is. Other than the location object tracking a URL you might no

Re: Intent to implement and ship: document.origin

2015-03-17 Thread Jonas Sicking
Pinging this old thread since nothing seems to have happened since it was last discussed. My recommendation is still to make location.origin return the "origin of the document" rather than "the origin of the URL". I would be surprised if that didn't fix many more pages than it broke. I think maki

Re: Intent to deprecate: persistent permissions over HTTP

2015-03-17 Thread Martin Thomson
On Tue, Mar 17, 2015 at 12:05 PM, Aryeh Gregor wrote: > 1) SNI is reportedly still not usable if you care about IE on XP. > This means HTTPS is not usable on shared hosting, which is most small > sites, unless you don't care that your site doesn't load in IE on XP. > This is also a problem for lar

Re: Intent to deprecate: persistent permissions over HTTP

2015-03-17 Thread Aryeh Gregor
On Thu, Mar 12, 2015 at 3:56 PM, Adam Roach wrote: > As an aside, the first three are not just fixable, but actually fixed within > the next few months: https://letsencrypt.org/ That seems like a huge step forward. But putting my ex-sysadmin hat on -- assuming it works as advertised, there are s

Re: Intent to deprecate: persistent permissions over HTTP

2015-03-17 Thread Aryeh Gregor
On Mon, Mar 16, 2015 at 3:24 PM, Eric Rescorla wrote: > Lots of people have the cameras in their rooms pointing at them even when > they are not using the computer, and so the camera can be used to spy on > them (Again, I refer you to Checkoway's description of "ratting" [1]). This > might be more