Confidence
4- Public role
- Current public evidence covers 2 domain references, 1 public website, 3 supporting public references; services, assets, and relationship context should be read with that evidence boundary.
- Information type
- IETF-W3C appears with 2 domain references, 1 public website, 3 supporting public references but no confirmed operator yet; BTW tracks it to link these public clues to a responsible organisation and its relationships.
Related details
- Public network record
Public source record
Last updated: 2026-06-19
Current status
Website
Services
1People & contacts
1Related research
27- SVG 2’s new CR snapshot leaves three features at risk
W3C has reopened the implementation stage for SVG 2, eight years after its previous published Candidate Recommendation snapshot; the next decision will depend on evidence, including whether localized descriptions survive.
Primary articlePublished 2026-10-06 - SensorThings Gains an SSN Relationship Map, Not a Round-Trip Guarantee
W3C has added a seven-row navigation crosswalk to its sensor ontology draft. It makes a migration choice visible, while leaving the conversion and its evidence to the teams that operate it.
Primary articlePublished 2026-09-29 - Seven W3C Directors Elected by Members Are Not Standards Delegates
W3C's 2026 election changes the people who oversee its corporation. It does not hand seven employers the Web's technical agenda. The consequential question is how the incoming directors distinguish the organizations that put them forward from the institution to which they now owe a duty.
Primary articlePublished 2026-09-28 - A Web API Call Is Not a Browser Permission
A page can ask a browser for a capability. The moment of asking is visible in application code; the point at which the browser decides what to allow is a different event. A revised W3C draft now draws that distinction into its simplest Web threat model.
Primary articlePublished 2026-09-28 - YAML-LD’s New Security Warning Puts the Parser Outside the Conformance Claim
A few lines of linked-data YAML can become a much larger tree before an application sees the data it intended to check. W3C’s latest draft makes that risk explicit, but the implementation decision remains with the operator.
Primary articlePublished 2026-09-28 - GPC’s Public Support File Is Not a Receipt for a Privacy Choice
The W3C’s latest Global Privacy Control Working Draft describes a request a browser can send and a declaration a website can publish. Neither record, on its own, says what happened to the person’s data after the request arrived.
Primary articlePublished 2026-09-28 - A SPARQL Graph Store Draft Makes Two Client Defaults Visible
W3C’s September revision widens the RDF format a server may return when a client omits `Accept`, and spells out UTF-8 decoding for an indirectly named graph. Neither change gives a client permission to write.
Primary articlePublished 2026-09-28 - EPUB’s Portable Notes Arrive Without Portable Trust
The latest EPUB Annotations draft gives reading systems a sharper security warning. A note can move between devices; the evidence that it belongs to a particular book and author does not move automatically with it.
Primary articlePublished 2026-09-27 - RDF 1.2 Gives a Quoted Statement a Place Without Making It a Fact
A knowledge graph may need to preserve a disputed statement without adopting it. W3C's latest RDF 1.2 Semantics draft makes that distinction visible at the level where software decides what a graph actually says.
Primary articlePublished 2026-09-27 - WCAG 3 Draws One Conformance Line. Policy Still Chooses What to Demand.
W3C's September draft separates a proposed single accessibility-conformance threshold from reporting tiers and the choices made by policymakers. That separation makes the next accountability question less about a badge and more about who selects the requirements for a particular service.
Primary articlePublished 2026-09-27 - A Credential Threat List Is Not a Control Ledger
W3C has expanded the risks around verifiable credentials into a separate draft note. Its most useful distinction is not a new cryptographic promise, but a map of decisions that issuers, wallet makers and verifiers still have to make.
Primary articlePublished 2026-09-26 - A Browser Can Keep a Site’s Bargain Without Keeping the User
A small revision to a W3C TAG draft draws a consequential line: a web agent may enforce a promise made to one service, but the service does not thereby acquire the person’s other data or their way out.
Primary articlePublished 2026-09-26 - ODRL’s Next Test Is Whether Two Policy Engines Agree
W3C’s workshop report asks for more than a common rights vocabulary. It proposes a way to compare what independent software actually decides when it processes the same policy.
Primary articlePublished 2026-09-26 - W3C’s Shorter Status Pointer Leaves a Larger Verification Decision
A new draft pares a credential’s status reference down to a base address and an index. The verifier must still decide what question it is asking and which signed list can answer it.
Primary articlePublished 2026-09-24 - W3C Approved Two French WCAG Translations. Their Pages Still Say Candidate
Two newly updated accessibility translations have two status labels on the same W3C pages. The difference is small in typography and large in document control: an adopting organization needs to know whether it is reading a candidate for review or the version W3C has authorized.
Primary articlePublished 2026-09-24 - SHACL Can Derive a Triple Without Naming the Rule That Made It
A data statement produced by a rule can look identical to one supplied by a source. W3C's new SHACL 1.2 Inference Rules draft provides a way to keep the producing rule attached, but makes that trace optional. The distinction matters wherever a derived statement leaves the rule engine and influences a decision.
Primary articlePublished 2026-09-24 - WebAuthn’s Remote Client Can Validate the RP ID. The Local Permission Cannot Prove It Did
The first public draft of WebAuthn Level 4 proposes a careful handoff for remote-desktop sign-ins: a local browser may use client data supplied by a remote machine, but only after a per-origin grant. That grant opens the local capability. It does not preserve evidence of the remote origin decision on which the ceremony now depends.
Primary articlePublished 2026-09-23 - WebAuthn’s 2026 Rejoin Handoff: The Governance Receipt Behind a New Participation Cycle
The Web Authentication Working Group’s 11 September 2026 recharter begins a new institutional phase for WebAuthn. The central challenge is not simply continuing technical discussion; it is preserving a reliable record of how an approved charter becomes active participation and how that participation connects to Patent Policy obligations. A privacy-safe rejoin-and-commitment receipt provides a practical model for maintaining that chain without confusing charter approval, grace-period activity, formal rejoin and renewed licensing commitments.
Primary articlePublished 2026-09-21 - W3C Asked for Horizontal Review. Its Publishing Charter Is Not Yet at AC Review
Five review tickets opened on 17 September around a proposed successor charter for W3C’s Publishing Maintenance Working Group. That is a meaningful procedural event, but not the event that authorises a new charter. The group is still operating under its existing mandate through 5 February 2027, while the proposed scope, dates and obligations remain a draft in refinement.
Primary articlePublished 2026-09-20 - W3C’s LLM Note Assigns Personal Responsibility—but Not an Accountability Process
The W3C Advisory Board’s new note contains a strong sentence: each person remains responsible for work they share, whether or not a large language model helped produce it. The status paragraph contains an equally important limit. The document is an Advisory Board Group Note, endorsed neither by W3C itself nor by its Members. Between those two statements sits the real governance question: what turns sensible advice into a rule that a working group can apply, review and correct?
Primary articlePublished 2026-09-20 - W3C’s Browser Portability Group Starts With a Report, Not a Standard
An iPhone user can now move selected Safari data into another browser through a documented export-and-import path. That is a real product capability. The W3C Browser Data Portability Community Group, launched on 15 September, is something else: a place to discuss principles and perhaps publish a Community Group Report. The distinction is the story, because a report can clarify the problem without yet carrying the authority of a standard, a legal obligation, a vendor commitment or a tested implementation.
Primary articlePublished 2026-09-20 - HTTP/2 Rapid Reset: The Protocol Was Revised. Who Proves the Repair Reached the Internet?
The HTTP/2 Rapid Reset episode exposed a gap that standards documents cannot close on their own. A protocol rule can permit a sequence of actions; a security researcher or operator can show how that sequence becomes an attack; a working group can review the behavior; and vendors can ship fixes. None of those steps, separately or together, proves that every exposed service has stopped accepting the dangerous path. The repair becomes durable only when implementation releases, package updates, operator controls and measurement converge.
Primary articlePublished 2026-09-10 - IETF–W3C: A Relationship Record, Not a Single Institution
The label “IETF–W3C” compresses two standards institutions into one directory entry. The public record supports a narrower description: the organizations have documented channels of cooperation, but the evidence reviewed does not establish one legal entity, one administrative owner, or one universal remedy for disputes involving both.
Primary articlePublished 2026-09-10 - TLS Renegotiation Was Repaired. Deployment Closure Is a Separate Claim.
The IETF repaired a dangerous ambiguity in TLS renegotiation. That repair changed the protocol. It did not, by itself, prove that every older library, appliance, endpoint and application path had stopped accepting the unsafe behavior.
Primary articlePublished 2026-09-10 - IETF-W3C Is Not One Institution: Authority Depends on the Instrument
The label IETF-W3C suggests a single governance center. The public record describes something more fragmented: the IETF standards process, the IETF Administration LLC, and W3C’s technical and membership structures assign different powers to different bodies. That distinction determines who can decide, who can object, and what remedy is actually available.
Primary articlePublished 2026-09-09 - Standards Become Infrastructure When Operators Must Carry Their State
IETF standards do not operate networks. They define the state machines, security dependencies and recovery procedures that networks must implement if they are to interoperate. That distinction matters when a protocol becomes part of the Internet’s operating surface: continuity no longer belongs to a standards body alone, but to implementers, operators, measurement systems and the institutions that maintain the specifications.
Primary articlePublished 2026-09-09 - W3C Calls Its 2026 Survey Anonymous. Both Forms Still Ask for an Email
An anonymous questionnaire can ask hard questions because the answer is not supposed to point back to the person. W3C’s new member and wider-community surveys make that promise, then each invites respondents to leave an email address for a follow-up interview. Nothing public shows that an answer has been exposed or improperly joined. The problem is more exact: readers cannot inspect the boundary that keeps the contact field from becoming an identity key. W3C should publish that separation rule while the survey is still open.
Primary articlePublished 2026-09-08
