This specification defines the Link-Template HTTP header field, providing a means for describing the structure of a link between two resources, so that new links can be generated. Note to Readers The issues list can be found at https://github.com/mnot/I-D/labels/ link- template . The most recent (often, unpublished) draft is at https://mnot.github.io/I-D/link-template/ . Recent changes are listed at https://github.com/mnot/I-D/commits/gh- pages/link-template .
The Hypertext Transfer Protocol (HTTP) is a stateless application- level protocol for distributed, collaborative, hypertext information systems. This document specifies the HTTP/1.1 message syntax, message parsing, connection management, and related security concerns. This document obsoletes portions of RFC 7230.
To aid debugging, HTTP caches often append headers to a responsedetailing how they handled the request. This specification codifiesthat practice and updates it for HTTP's current caching model.
This document registers the secret-token URI scheme, to aid in the identification of authentication tokens.
This document describes a set of data types and associated algorithms that are intended to make it easier and safer to define and handle HTTP header and trailer fields, known as Structured Fields, Structured Headers, or Structured Trailers. It is intended for use by specifications of new HTTP fields that wish to use a common syntax that is more restrictive than traditional HTTP field values.
Google’s Privacy Sandbox proposals to change the Chrome browser in ways that are likely to further advantage them over other publishers and advertising platforms has attracted the attention of competition regulators, the online advertising industry, and critics of their platform power. At the same time, the Privacy Sandbox appears to answer a call from data protection regulators, privacy advocates and users for ‘privacy by design,’ moving in lockstep with its industry peers. How, then, should this behaviour be evaluated for abuse? I argue that there are several hurdles to considering the most controversial Privacy Sandbox proposal – blocking third-party cookies – as an abuse of market power. Furthermore, I propose that, because web browsers are an architecturally regulated market, competition regulators should distinguish unilateral behaviour by examining it in the context of other browsers’ behaviours, along with signals regarding consensus from the relevant standards bodies.
The Schrems II decision has created widespread uncertainty about the legality of cross-border data flows from Europe, especially in countries with extensive national security laws. This research uses the most recent guidance for evaluating such laws – the European Essential Guarantees – along with an analysis of post-Schrems II adequacy decisions to evaluate an Australian national security instrument, the ASIO computer access warrant. It highlights potential deficiencies and explores potential outcomes for Australia-Europe digital trade, concluding that an update to relevant Australian laws is the most reliable way for Australia to unblock the growth that digital trade promises.
The Exploring Synergy between Content Aggregation and the Publisher Ecosystem (ESCAPE) Workshop was convened by the Internet Architecture Board (IAB) in July 2019. This report summarizes its significant points of discussion and identifies topics that may warrant further consideration.
Browser and device fingerprinting are especially pernicious methods of online tracking, but most legal responses have not distinguished them from a more well- known mechanism, cookies, despite having a reputation as being ‘creepy’. I contend that they deserve separate consideration, owing to the distinct privacy challenges they present. In this paper I briefly explain what fingerprinting is, summarise how online trackers use it, and explore the privacy issues raised, especially as compared to cookies. I evaluate the current constraints on fingerprinting using Lessig’s norms/ market/architecture/law framework of regulation modalities. I then discuss why fingerprints should not only be considered as distinct from cookies, but should also be considered as sensitive data, deserving of a distinct legal response. Finally, I outline potential legal responses to fingerprinting, exploring their tradeoffs.
Section 1.1.1 of RFC 3986 defines URI syntax as "a federated and extensible naming system wherein each scheme's specification may further restrict the syntax and semantics of identifiers using that scheme." In other words, the structure of a URI is defined by its scheme. While it is common for schemes to further delegate their substructure to the URI's owner, publishing independent standards that mandate particular forms of URI substructure is inappropriate, because that essentially usurps ownership. This document further describes this problematic practice and provides some acceptable alternatives for use in standards.
This specification defines a "safe" preference for HTTP requests that expresses a desire to avoid objectionable content, according to the definition of that term by the origin server. Support for this preference by clients and servers is optional.
Many of us have held a vision of the Internet as the ultimate distributed platform that allows communication, the provision of services, and competition from any corner of the world. But as the Internet has matured, it seems to also feed the creation of large, centralised entities in many areas. This phenomenon could be looked at from many different angles, but this memo considers the topic from the perspective of how available technology and Internet architecture drives different market directions.