w3cping / privacy-threat-model

A target privacy threat model for the Web
https://w3cping.github.io/privacy-threat-model
Apache License 2.0
23 stars 7 forks source link

Definition of site doesn't include the scheme #2

Closed davidben closed 4 years ago

davidben commented 4 years ago

Treating http and https URLs as the same site doesn't seem great, given that http URLs are controlled by the network as well as the site owner. See also https://github.com/whatwg/url/issues/448