W3C

Edit comment LC-2024 for Mobile Web Best Practices Working Group

Quick access to

Previous: LC-2004 Next: LC-2028

Comment LC-2024
:
Commenter: casays <casays@yahoo.com>

or
Resolution status:

6) Section 4.3.6.2

The possibility to break the end-to-end security of an HTTPS
connection is unacceptable and must be forbidden. This jeopardizes the
set-up of mobile e-commerce, which had difficulties to get established
in part because of the point-to-point, hop-wise secure connection with
WTLS, and makes a sham of security for other applications that require it.

Besides, there is no guarantee that transformations performed by a
proxy preserve the content being exchanged between client and server
to a point that does not further disturb the secure exchange. As an
example, there is no explicit prohibition in the draft against turning
POST requests into GET ones, the resizing of images may make visual
captchas unreadable, and reordering elements may make forms or
security information difficult to figure out at the client side.
(space separated ids)
(Please make sure the resolution is adapted for public consumption)


Developed and maintained by Dominique Hazaël-Massieux (dom@w3.org).
$Id: 2024.html,v 1.1 2017/08/11 06:43:16 dom Exp $
Please send bug reports and request for enhancements to w3t-sys.org