Skip to content

Commit 8e2c025

Browse files
committed
Update 100_percent_https_roadmap.md
1 parent cb6629f commit 8e2c025

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

admin/100_percent_https_roadmap.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -57,6 +57,7 @@ No Read Down / No Write Up
5757
* Distinct invariants, but the web is very bad a data/code separation.
5858
* Even if we wanted to make an exception to Read Down (e.g. open data over http) it is impossible to guarantee that No Write Up isn’t also violated.
5959
- “optionally blockable” mixed content attempts this distinction, but XHR + JS is not strongly typed enough to allow read down without write up in an “open data” application
60+
* There is also metadata and other information leakage possible in a secure->insecure read operation
6061

6162
No Write Down
6263
-------------

0 commit comments

Comments
 (0)