ISSUE-20: If browsers apply UI Security heuristic without an explicit opt-in policy, should we always block and not have the unsafe UIEvent property

If browsers apply UI Security heuristic without an explicit opt-in policy, should we always block and not have the unsafe UIEvent property

State:
CLOSED
Product:
UI Security
Raised by:
Opened on:
2012-11-01
Description:
What should be the recommended default behavior for UI Security heuristics?

Block, or report (set unsafe flag on event)
Related Actions Items:
Related emails:
No related emails

Related notes:

This does not need to be specified - an open decision to implementers for experimentation if they desire.

Brad Hill, 25 Nov 2013, 22:32:23

Display change log ATOM feed


Daniel Veditz <dveditz@mozilla.com>, Mike West <mkwst@google.com>, Chairs, Wendy Seltzer <wseltzer@w3.org>, Samuel Weiler <weiler@w3.org>, Staff Contacts
Tracker: documentation, (configuration for this group), originally developed by Dean Jackson, is developed and maintained by the Systems Team <w3t-sys@w3.org>.
$Id: 20.html,v 1.1 2020/01/17 08:52:24 carcone Exp $