Re: [Captive-portals] CAPPORT meeting at IETF95 in Buenos Aires.

I'm interested in the Sandboxing point in section 4. I understand these to be designed as a pro-user security feature. In general I don't trust random network devices in hotels so I'll use a VPN. That leaves me open to malware attacks from the captive portal [1]. Deciding to put captive portals into a more-restrictive-than-usual sandbox then seems reasonable to me.

Can you explain the problems caused by sandboxing (I don't think I've ever experienced them)?

> Mark Nottingham is already working on a "problem statement" type draft with outlines some of this, but we'd like more viewpoints/ discussions.


> His initial submission is here: "Before You Log In, Here's A Brief Message From Our Sponsors!" - draft-nottingham-capport-problem (https://datatracker.ietf.org/doc/draft-nottingham-capport-problem/)

... and that's really just a regurgitation of what we previously put together at <https://github.com/httpwg/wiki/wiki/Captive-Portals>.  If people have suggestions, corrections, pull requests, etc. I'm all ears.


