@techreport{west-cookie-incrementalism-01, number = {draft-west-cookie-incrementalism-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-west-cookie-incrementalism/01/}, author = {Mike West}, title = {{Incrementally Better Cookies}}, pagetotal = 17, year = 2020, month = mar, day = 15, abstract = {This document proposes a few changes to cookies inspired by the properties of the HTTP State Tokens mechanism proposed in {[}I-D.west-http-state-tokens{]}. First, cookies should be treated as "SameSite=Lax" by default. Second, cookies that explicitly assert "SameSite=None" in order to enable cross-site delivery should also be marked as "Secure". Third, same-site should take the scheme of the sites into account. Fourth, cookies should respect schemes. Fifth, cookies associated with non-secure schemes should be removed at the end of a user's session. Sixth, the definition of a session should be tightened.}, }