The Web Application Security Working Group has published a First Public Working Draft of Post-Spectre Web Development. Post-Spectre, we need to adopt some new strategies for safe and secure web development. This document outlines a threat model we can share, and a set of mitigation recommendations.

