Contact emails
jkoka...@google.com

Explainer
None


Specification
None


Summary

There are known[1] security issues around charset auto-detection for 
ISO-2022-JP. Given that the usage is very low, and Safari does not support 
auto-detection of ISO-2022-JP, we will remove support for it to eliminate the 
security issues. [1]: 
https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/



Blink component
Blink>TextEncoding


Motivation

There are known[1] security issues around charset auto-detection for 
ISO-2022-JP. The use counter[2] shows that the auto-detection of ISO-2022-JP 
charset only happens around 0.000002% of page load. Given that usage is very 
low, and Safari does not support auto-detection of ISO-2022-JP, we will remove 
support for it to eliminate the security issues. [1]: 
https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/ 
[2]: https://chromestatus.com/metrics/feature/timeline/popularity/5244



Initial public proposal
None


TAG review
None


TAG review status
Not applicable


Risks




Interoperability and Compatibility

None


Gecko: Positive (https://github.com/mozilla/standards-positions/issues/1199)

WebKit: Shipped/Shipping

Web developers: No signals

Other signals:


WebView application risks

Does this intent deprecate or change behavior of existing APIs, such that it 
has potentially high risk for Android WebView-based applications?

None




Debuggability

None



Is this feature fully tested by web-platform-tests?
No


Flag name on about://flags
None


Finch feature name
None


Non-finch justification
None


Requires code in //chrome?
False


Tracking bug
https://issues.chromium.org/issues/40089450


Estimated milestones

No milestones specified



Link to entry on the Chrome Platform Status
https://chromestatus.com/feature/6576566521561088?gate=6587467307941888


This intent message was generated by Chrome Platform Status.

-- 
You received this message because you are subscribed to the Google Groups 
"blink-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to blink-dev+unsubscr...@chromium.org.
To view this discussion visit 
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/67f40d24.170a0220.25676e.144b.GAE%40google.com.

Reply via email to