4 ms·
PSL maintainer here: please don’t use the PSL! Yes, it’s weird to have a maintainer asking people not to use their project, but the PSL was a very specific (an
by sleevi 6y ago
PSL maintainer here: please don’t use the PSL!
Yes, it’s weird to have a maintainer asking people not to use their project, but the PSL was a very specific (and unfortunate) hack for a very specific (and unfortunate, and browser-created) problem. It is something we live with, not something we like. While the ideal world is “don’t use any list at all, use the protocols as God, the IETF, and IANA intended”, if you are going to use a list, using the IANA list, updated daily, is much better than the PSL.
Do not use the PSL for anything that is not “cookies abusing the Host header”
https://github.com/sleevi/psl-problems https://github.com/sleevi/psl-problems
- methyl 6y agoIt has pretty strong usecase in SEO where you want to determine number of unique root domains that are linking to some page.
- Lvl999Noob 6y agoAre you still adding suffixes to the list? If so, wouldn't refusing to add new suffixes help with the issue? If no new organisation can make use of PSL to link their subdomains, then they are only left with SOP. Since the list stays like it is now, no existing websites, depending on the list suddenly break down.
- sleevi 6y agoWe are. Deliberate sabotage like that would take quite a while before it was noticed, however, and it wouldn’t magically fix cookies and how people use them. To the extent it is used by cookies, we still want to maintain a fair and equitable solution. However, we also want to actively discourage any new users or use cases, to the extent possible, while we also try to fix cookies. Ideas like https://github.com/privacycg/first-party-sets https://github.com/privacycg/first-party-sets provide a possible model. While FPS doesn’t directly address this, as part of keeping a narrow scope, the approach to explicitly expressing boundaries is one that has the best viable path. However, that’s effectively “Deprecate the Host option for cookies”, so... that’s a big task. Simply sabotaging the PSL doesn’t force the problem to be solved, so mostly, it’s an education campaign of “We made a mistake; learn from ours, rather than repeating it.”
- pbronez 6y agoThe annotations and formatting make your list way more useful than the official IANA one. I appreciate the links to learn more about each TLD.
- tialaramex 6y agoInteresting. Does this mean that - without your Google hat on at least - you would prefer that references to the PSL were removed from the CA/B BRs as well? WebAuthn ends up relying on the PSL as well (via a concept of "registrable domains" and WHATWG). Presumably you'd want that to just require Same Origin instead?
- sleevi 6y agoYes. The WebAuthN case in particular is quite unfortunate, and one I tried to discourage early on (along with the whole app facets approach)