Sub-domain granularity: the poverty of the domain name as the only hook for security

Tim Berners-Lee <[email protected]>
Newsgroups gmane.org.w3c.tag
Message-ID <[email protected]>

The HSTS spec  http://tools.ietf.org/html/rfc6797 is a good start but it is not useful for serious websites which have many separate parts which have to have different policies, management, etc.

Similarly the Same Origin Policy in general is very hampering and in that it only works at the domain level not at any path level.   It would have been not very much harder to set both of them up to work on subtrees within the domain, and both would have been much more powerful and useful.  I propose they both be fixed in future. 

The result of these two has been a pain and many perverse incentives and side-effects, for just one example github.com/linkdata having to half-move to linkeddata.github.com (which is now a mess and loses locality of linking between the two) and w3.org not being able to move to HTTPS at all because of being unable to apply HTTS path by path. 

Just saying.

Timbl
signature.asc (application/pgp-signature, 495 B)
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org

iQEcBAEBAgAGBQJVBtqCAAoJEDRNlmYRd57nQw0H/3m+dNcJ/wLYib5d+ELhjBfH
KnnfGRoIihpZCosDC4lMZ8yKQ/S/C/XGXAaUS/r91KiRbUkJCbWgxtHOd6f4hVdF
Wqm4VifaS69HVAZ/pR1A8Zj6vrRayANVuJgV/QGACwmmzE0QmZJ4+AN9QXYUI4S8
HKS8A0P32wkovmfXQ5rpNLo2eqcf2QLt/Qql2Cdm4ianEgUGkUKQEJrNShkwk6c0
CMQEwRx0ypibuM2vFBuiM8gq2hutZTOqyd3p2bwt3hQVdmY7NIW6FEEYMKl211mo
Ung+2TjpROd2sCag3G/JAmrBLwj3bl5LRj0fyMyfwblKFtws0r07JnVbrWeHYI0=
=jbxd
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.