All resources used in the context of Solid Authentication and Authorization MUST use a secure protocol.
Namely, a WebID used for Authentication MUST use the https protocol. That is true of both client and user WebIDs.
Currently, the specification states: "a WebID is a HTTP URI". I couldn't find any specific requirements about security in transit.
I appreciate that it seems a bit like stating the obvious, but I reckon it is fundamentally important enough to require an extension of section 3, probably with a 3.2 Encryption of WebIDs in transit.
See also: https://www.ncsc.gov.uk/collection/cloud-security/implementing-the-cloud-security-principles/data-in-transit-protection
All resources used in the context of Solid Authentication and Authorization MUST use a secure protocol.
Namely, a WebID used for Authentication MUST use the https protocol. That is true of both client and user WebIDs.
Currently, the specification states: "a WebID is a HTTP URI". I couldn't find any specific requirements about security in transit.
I appreciate that it seems a bit like stating the obvious, but I reckon it is fundamentally important enough to require an extension of section 3, probably with a 3.2 Encryption of WebIDs in transit.
See also: https://www.ncsc.gov.uk/collection/cloud-security/implementing-the-cloud-security-principles/data-in-transit-protection