Skip to content

Commit

Permalink
Update TAG S&P questionnaire (#62)
Browse files Browse the repository at this point in the history
  • Loading branch information
DCtheTall authored Nov 22, 2022
1 parent 5f38d72 commit 8a169f1
Showing 1 changed file with 6 additions and 2 deletions.
8 changes: 6 additions & 2 deletions TAG-S&P-questionnaire.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,8 +98,12 @@ See 3.1.

### 3.3. Same-Origin Policy Violations

By requiring the __Host- prefix, this proposal makes partitioned cookies scheme- and hostname-bound.
However, even cookies with the __Host- prefix can still be sent to different ports (though this may change if [Origin-Bound Cookies](https://github.com/sbingler/Origin-Bound-Cookies) is enabled).
Like all other cookies, partitioned cookies can be shared across different subdomains using the Domain attribute.
Partitioned cookies require Secure, so they are not accessible in insecure origins.

In an effort to bring cookies closer to using origin as the security boundary, we previously proposed that partitioned cookies be required to be scheme- and hostname-bound, unlike other cookies.
However, we received feedback from site authors that this would make it too cumbersome to migrate legacy systems to the more privacy-forward partitioned cookies.
In order to alleviate this concern, we have since removed that requirement.

### 3.4. Third-Party Tracking

Expand Down

0 comments on commit 8a169f1

Please sign in to comment.