%% You should probably cite draft-west-cookie-incrementalism-01 instead of this revision. @techreport{west-cookie-incrementalism-00, number = {draft-west-cookie-incrementalism-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-west-cookie-incrementalism/00/}, author = {Mike West}, title = {{Incrementally Better Cookies}}, pagetotal = 9, year = 2019, month = may, day = 7, abstract = {This document proposes two changes to cookies inspired by the properties of the HTTP State Tokens mechanism proposed in {[}I-D.west-http-state-tokens{]}. First, cookies should be treated as "SameSite=Lax" by default. Second, cookies that explicitly assert "SameSite=None" in order to enable cross-site delivery should also be marked as "Secure".}, }