Re: [DNSOP] Public Suffix List

Jamie Lokier <jamie@shareable.org> Tue, 10 June 2008 12:31 UTC

Return-Path: <dnsop-bounces@ietf.org>
X-Original-To: dnsop-archive@lists.ietf.org
Delivered-To: ietfarch-dnsop-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 33C053A6A5D; Tue, 10 Jun 2008 05:31:52 -0700 (PDT)
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id DB6B53A6A5D for <dnsop@core3.amsl.com>; Tue, 10 Jun 2008 05:31:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.043
X-Spam-Level:
X-Spam-Status: No, score=-4.043 tagged_above=-999 required=5 tests=[AWL=-1.444, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id x64C6or1Onqw for <dnsop@core3.amsl.com>; Tue, 10 Jun 2008 05:31:50 -0700 (PDT)
Received: from mail2.shareable.org (mail2.shareable.org [80.68.89.115]) by core3.amsl.com (Postfix) with ESMTP id E904B3A6A3B for <dnsop@ietf.org>; Tue, 10 Jun 2008 05:31:49 -0700 (PDT)
Received: from jamie by mail2.shareable.org with local (Exim 4.63) (envelope-from <jamie@shareable.org>) id 1K6319-0007e3-MQ; Tue, 10 Jun 2008 13:32:03 +0100
Date: Tue, 10 Jun 2008 13:32:03 +0100
From: Jamie Lokier <jamie@shareable.org>
To: Adrien de Croy <adrien@qbik.com>
Message-ID: <20080610123203.GA28565@shareable.org>
References: <484CFF47.1050106@mozilla.org> <20080609142926.GC83012@commandprompt.com> <484D4191.104@mozilla.org> <20080609162426.GA2596@shareable.org> <484D5A44.30603@mozilla.org> <20080609163659.GC2596@shareable.org> <484D5F3B.8040902@mozilla.org> <20080610100917.GA25910@shareable.org> <484E53B2.6030404@mozilla.org> <484E6F40.6010805@qbik.com>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <484E6F40.6010805@qbik.com>
User-Agent: Mutt/1.5.13 (2006-08-11)
Cc: dnsop@ietf.org, Gervase Markham <gerv@mozilla.org>, ietf-http-wg@w3.org
Subject: Re: [DNSOP] Public Suffix List
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: dnsop-bounces@ietf.org
Errors-To: dnsop-bounces@ietf.org

Adrien de Croy wrote:
Allow some "safe" cross-site 
> cookies?  What happens when it doesn't do that?  Do people even care 
> enough about that to live with this solution?

I must admit, I don't see what's wrong with disabling cross-site
cookies entirely.

If two related domains want to transfer credentials, sessions etc.,
there are other mechanisms to do it.

> In the end what will be the deciding factors?  I see users dumping FF3 
> when it doesn't work with the websites they know and trust.  I see the 
> reviews bemoaning compatibility issues.  Mozilla needs to be careful 
> when introducing something like this that can create many compatibility 
> issues where the previous version didn't have them.  In the end if some 
> large jurisdictions refuse to play along, where does that leave 
> Mozilla's users?  Looking for another browser perhaps..  Unless Mozilla 
> feels it has too many users, I'd urge caution in that area.

Perhaps the list should be used to implement a warning, easily
overridden per site, like the other cookie dialogs which Mozilla pops
up, rather than a hard block.

As a user I might prefer that.  I already like being able to say
"no thanks" to cookies on sites where I don't see any need.

-- Jamie
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop