I am also very interested on the topic -mobile security- and available for any discussion. I think one of the difficulties here is also that by saying native we sometimes/mostly refer to an hardware component or a software function with hardware support. Since I guess the standard cannot be based on a specific hardware feature, I believe some and correct level of abstraction is needed based on, as Dominique pointed out, the gaps seen by different industries, so the spec may not directly depend on whatever hardware there is, but the security concepts that is introduced by having such software/hardware components in the system.



> As announced by Wendy, I am now joining the Web Security IG team and I shared with Adam and Wendy few topics I believe this IG could discuss. So here is a proposal of topics we could focus in the coming months, to bring back this IG to life :)
> -       Mobile security
> We should support the web & mobile IG [1] to understand what are the
> main security weaknesses in the web app model, compared to native app
> model. This would help W3C to fill the gap in terms of security
> feature for the mobile web.

As you know, I'm very interested on this topic, and will be available to
help; a big part of the work that needs to be done here is identify what
content/servie providers see as gaps, and document which of these gaps
are real, and which have solutions but that are not sufficiently



