<div dir="ltr">Apologies for digging up an old thread; I didn't see it until now.<br><br>On Thu, Jul 24, 2014 at 7:59 AM, Alexey Proskuryakov <<a href="mailto:ap@webkit.org">ap@webkit.org</a>> wrote:<br>> In other words, how is "active content" defined here?<br>
<br>Note that the WebAppSec WG is working on a mixed content spec that drops the "active"/"passive" distinction in favor of "stuff we can block without breaking the web"/"images": <a href="http://w3c.github.io/webappsec/specs/mixedcontent/#categories">http://w3c.github.io/webappsec/specs/mixedcontent/#categories</a> Feedback on that document would be welcome.<br>
<br>As Michael notes in his response, Chrome is busy tightening its implementation to match that spec. Some details on that in <a href="https://groups.google.com/a/chromium.org/d/msg/security-dev/Uxzvrqb6IeU/wb51F3nV7csJ">https://groups.google.com/a/chromium.org/d/msg/security-dev/Uxzvrqb6IeU/wb51F3nV7csJ</a><br>
<br>-mike</div>