Re: New web site

Jay Daley <[email protected]> Sun, 24 May 2026 19:29:49 +1200
Newsgroups gmane.ietf.general
Message-ID <[email protected]>
Hi Stephen

> On 24 May 2026, at 12:50, Stephen Farrell <[email protected]> wrote:
> 
> On 24/05/2026 01:42, Nicolas Giard wrote:
>> You can report any accessibility issues, and we'll do our best to fix them,
>> but the issue must stem from actual accessibility reasons / usability
>> concerns for people with severely constrained resources, not just because
>> "I don't like JavaScript".
> 
> Where is the policy that underlies that "must" above documented?

Apologies, the "must" part should have been worded better - a better way of putting it is that full use of this particular site requires Javascript and we won’t be trying to replicate all the JS features with non-JS features even if tickets are added asking for that.

If you’re asking where is the policy that says we don’t have to provide strict JS/non-JS feature equivalence, then there isn’t one, but at the same time there isn’t one that says we have to do that.  Support for non-JS has been discussed at open Tools meetings a number of times, the most recent being the open meeting at IETF 124 Montreal and the clear community feedback in those meetings has been that JS is a normal and intrinsic part of the web experience and trying to make all of our sites fully support non-JS is not reasonable.

If you’re asking why we have JS only features then it’s because JS is a vastly more capable tool than plain HTML/CSS and it therefore enables things that cannot be done otherwise and with a better user experience.  That doesn’t mean we’re incautious about the use of it, explained below.

> And "I don't like JS" is not at all the issue, it's about attack
> surface.

I think that’s oversimplifying a complicated landscape.  The IETF sites do not serve adverts, they control all of their JS and they do not serve any JS that talks to a third party service.  The IETF Privacy Statement is clear on that. To be clear, I am not saying that running JS does not increase the attack surface, just noting that our use of JS is intentionally very tight and aimed at minimising the attack surface that JS introduces.  


cheers
Jay

> 
> Thanks,
> S.
> 

-- 
Jay Daley
IETF Executive Director
[email protected]