I've been conversing with Yngve about HTTPOnly and related, his current RFC draft that covers cookies:


His current draft is aimed at improving cookie security and proposes to not permit the "parent"-domain type of distribution for cookies; some background on this is here:


He also mentioned contemplating making the "secure" flag on by default for any cookie set over SSL/TLS.  This sounds like a good idea to me, but would obviously break some web applications.

And I thought it would be good to add the HTTPOnly flag to the spec or write a separate spec, as there currently doesn't appear to be one anywhere to be had (which undoubtedly is what is contributing to it's lack of standard implementation across the browsers).

So I believe there's an opportunity to here to improve cookie security and get it into an RFC so that browser vendors can uniformly implement a more secure cookie model.  I'm guessing any changes that will break existing sites will not be adopted or welcomed, so to that end, I think it may be prudent to consider implementing changes strictly to Cookie2, so that Cookie can be phased out and security-progressive sites can instead implement Cookie2 exclusively.

Any thoughts on any of this?

- Bil

