Re: [Web Crypto Next] Status and next steps

Hi Virginie,

During the 20Y+ we have bought stuff on the web and paid with credit cards,
the method haven't changed.  That is, in spite of a billion s.c. EMV-cards
in circulation, on the web we are currently stuck with highly inconvenient
and (any number of times proved) unsecure CNP (Card Not Present) schemes.

To me it looks like a task for your particular sector coming up with a
proposal on how to address this pretty obvious use case.

Apple have advanced the state of on-line payments by a mile in iPhone 6,
but AFAIK it doesn't include the web.

Sincerely,
Anders Rundgren

On 2014-10-10 14:57, GALINDO Virginie wrote:
> Dear all,
>
> A short status of where we are in the Web Crypto Next Workshop follow up.
>
> -As announced [1], a wiki has been set up to receive your ideas about the re-chartering of Web Crypto WG, taking into account the findings of the Web Crypto Next Workshop.
>
> -The workshop report will soon made available by Harry Halpin probably next week, it will be circulated on this mailing list for review during one week.
>
> -During  W3C TPAC meeting scheduled on 26-31 Oct [2] , there will be some actions to socialize the workshop findings with W3C members (during security related WG, during the AC representatives meeting, and during Wednesday Break-Out sessions)
>
> -Still during the TPAC week, Wendy, W3C security domain leader has organized a conversation with Web App Sec and Web Crypto chairs to see how we could re-charter both groups in synchronization, taking into account workshop findings.
>
> If you need some help to contribute, give your opinion, better understand direction, do not hesitate to ask question to Wendy, Harry, or myself !
>
> Regards,
>
> Virginie Galindo
>
> gemalto
>
> signing as chair of web crypto / chair of web security ig
>
> [1] http://lists.w3.org/Archives/Public/public-web-security/2014Oct/0001.html
>
> [2] http://www.w3.org/2014/11/TPAC/
>
> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
> This message and any attachments are intended solely for the addressees and may contain confidential information. Any unauthorized use or disclosure, either whole or partial, is prohibited.
> E-mails are susceptible to alteration. Our company shall not be liable for the message if altered, changed or falsified. If you are not the intended recipient of this message, please delete it and notify the sender.
> Although all reasonable efforts have been made to keep this transmission free from viruses, the sender will not be liable for damages caused by a transmitted virus.

Received on Sunday, 12 October 2014 05:42:36 UTC