%% You should probably cite draft-ietf-httpbis-rfc6265bis instead of this I-D. @techreport{ietf-httpbis-cookie-alone-01, number = {draft-ietf-httpbis-cookie-alone-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-httpbis-cookie-alone/01/}, author = {Mike West}, title = {{Deprecate modification of 'secure' cookies from non-secure origins}}, pagetotal = 6, year = 2016, month = sep, day = 5, abstract = {This document updates RFC6265 by removing the ability for a non- secure origin to set cookies with a 'secure' flag, and to overwrite cookies whose 'secure' flag is set. This deprecation improves the isolation between HTTP and HTTPS origins, and reduces the risk of malicious interference.}, }