11/28 Minutes
[fwd] Updated passwords in the clear (from: dorchard@bea.com)
A Dilbert for us
ACTION-293 : updated write-up on browser lock down available on the wiki
ACTION-304: Secure Letterhead prototype
ACTION-305 : discuss usability testing with Maritza for browser lock down
ACTION-318: Draft a new subsection to section 7 discussing the mixing of trusted/untrusted information in the UI
- Doyle, Bill (Tuesday, 27 November)
- Johnathan Nightingale (Monday, 26 November)
- Doyle, Bill (Monday, 26 November)
- Johnathan Nightingale (Wednesday, 14 November)
- Doyle, Bill (Wednesday, 14 November)
- Mary Ellen Zurko (Wednesday, 14 November)
- Doyle, Bill (Wednesday, 14 November)
- Mary Ellen Zurko (Wednesday, 14 November)
- Mary Ellen Zurko (Wednesday, 14 November)
ACTION-321 cipher suite strength
ACTION-321 cipher suite strength - looking for review some ISO docs
ACTION-323 Respond with a proposal on issue 115 and ACTION-328 Propose techniques for not obviously spoofable audio presentation based on discussion above suitable for 8.3.2
ACTION-324 Drop success criteria into wiki
ACTION-325 Coordinate with hypertext CG re a11y issues
ACTION-326: Transfer RobustSharedSecret into section 8.2
ACTION-329 Review 8.2 to ensure suitability of language in non-visual contexts Bruno von Niman 2007-11-12
ACTION-330 Requirements for usability testing for conformace
ACTION-331 Work toward worked example of usability testing for conformance
ACTION-332 OPEN Elaborate on ISSUE-3 Stephen Farrell 2007-11-13
ACTION-333 OPEN Elaborate on ISSUE-4 Stephen Farrell 2007-11-13
ACTION-335 logotypes and ISSUE-96 discussion
- michael.mccormick@wellsfargo.com (Monday, 19 November)
- Serge Egelman (Monday, 19 November)
- Hallam-Baker, Phillip (Monday, 19 November)
- Hallam-Baker, Phillip (Monday, 19 November)
- Michael Versace (Saturday, 17 November)
- Dan Schutzer (Saturday, 17 November)
- Mary Ellen Zurko (Friday, 16 November)
- Johnathan Nightingale (Wednesday, 14 November)
- Hallam-Baker, Phillip (Wednesday, 14 November)
- Hallam-Baker, Phillip (Wednesday, 14 November)
- Hallam-Baker, Phillip (Wednesday, 14 November)
- Serge Egelman (Wednesday, 14 November)
- Serge Egelman (Wednesday, 14 November)
- Ian Fette (Wednesday, 14 November)
- Serge Egelman (Tuesday, 13 November)
- Hallam-Baker, Phillip (Tuesday, 13 November)
- Hallam-Baker, Phillip (Tuesday, 13 November)
- Ian Fette (Tuesday, 13 November)
- Johnathan Nightingale (Tuesday, 13 November)
- Ian Fette (Tuesday, 13 November)
- Dan Schutzer (Tuesday, 13 November)
- Serge Egelman (Tuesday, 13 November)
- Hallam-Baker, Phillip (Tuesday, 13 November)
- Hallam-Baker, Phillip (Tuesday, 13 November)
- Ian Fette (Tuesday, 13 November)
- Serge Egelman (Monday, 12 November)
- Ian Fette (Friday, 9 November)
ACTION-337 Prod serge about SSL error study; re ISSUE-107 Rachna Dhamija 2007-11-13
ACTION-338: Issues for safe browsing mode
ACTION-339 Proposal for authoring best practice for ISSUE-110
ACTION-342 Write up "comment disposition process" in wiki
ACTION-344, ISSUE-120: Proposed normative material on audio logotypes
ACTION-381: Draft a new subsection to section 7 discussing the mixing of trusted/untrusted information in the UI
Agenda: WSC WG distributed meeting, Wednesday, 2007-11-14
Agenda: WSC WG distributed meeting, Wednesday, 2007-11-21
Agenda: WSC WG distributed meeting, Wednesday, 2007-11-28
Citeable reference for Emperor?
Comments on Draft
Comments on draft documents posted to the WSC wiki
Comments on draft passwords-in-the-clear finding
document.cookie
Fwd: Agenda: WSC WG distributed meeting, Wednesday, 2007-11-28
Introduction
ISSUE-106: Certificate / URL matching
ISSUE-111 (Re: belated remarks on PII Bar)
ISSUE-115 (Re: Agenda: WSC WG distributed meeting, Wednesday, 2007-11-28)
ISSUE-115 Mixing of security information and content in non-visual environments?
ISSUE-115: Mixing of security information and content in non-visual environments? [Techniques]
ISSUE-117 (serge): Eliminating Faulty Recommendations [All]
- Mary Ellen Zurko (Wednesday, 21 November)
- Mary Ellen Zurko (Wednesday, 21 November)
- Thomas Roessler (Tuesday, 20 November)
- Luis Barriga (Tuesday, 20 November)
- Ian Fette (Tuesday, 20 November)
- michael.mccormick@wellsfargo.com (Tuesday, 20 November)
- Maritza Johnson (Tuesday, 20 November)
- Ian Fette (Tuesday, 20 November)
- michael.mccormick@wellsfargo.com (Monday, 19 November)
- Ian Fette (Monday, 19 November)
- michael.mccormick@wellsfargo.com (Monday, 19 November)
- Johnathan Nightingale (Wednesday, 14 November)
- Serge Egelman (Monday, 12 November)
- michael.mccormick@wellsfargo.com (Monday, 12 November)
- Mary Ellen Zurko (Friday, 9 November)
ISSUE-130 (Trust Anchors): Trust Anchor Consistency Across Devices? [Techniques]
ISSUE-131 (Code outside browser): Executing code outside of browser in 8.3.2.3 is vague / scary [All]
ISSUE-132: Update Section 10.1 of wsc-xit with information from updated browser lock down wiki page
- michael.mccormick@wellsfargo.com (Thursday, 29 November)
- michael.mccormick@wellsfargo.com (Wednesday, 28 November)
- Ian Fette (Wednesday, 28 November)
- Timothy Hahn (Wednesday, 28 November)
- Mary Ellen Zurko (Wednesday, 28 November)
- Timothy Hahn (Tuesday, 27 November)
- Doyle, Bill (Monday, 26 November)
- michael.mccormick@wellsfargo.com (Monday, 26 November)
- Timothy Hahn (Monday, 26 November)
- Ian Fette (Monday, 26 November)
- Dan Schutzer (Monday, 26 November)
- Mary Ellen Zurko (Monday, 26 November)
- Web Security Context Working Group Issue Tracker (Friday, 16 November)
ISSUE-39 cooperate with WAI-ARIA \'politeness\' (from public comments)
ISSUE-3: Can XQuery/XPath contribute to attack vectors?
ISSUE-4: FTP instead of HTTP?
ISSUE-96 Should support for logotypes be a SHOULD or a MAY?
Meeting record: 2007-11-14
Meeting record: WSC WG f2f 2007-11-05
Meeting record: WSC WG f2f 2007-11-06
Meeting record: WSC WG weekly 2007-11-21
Phishing scam uses AOL address to target eBay users
Proposal for ISSUE-130: TLS across multiple devices
Slashdot | Cross-Selling Online Scams and Security Issues
Transition announcements: FPWD of xit, LC of usecases, and publication of threats
UPSEC and LEET workshops
WSC Open Action Items
WSC WG Call for November 7th 2007
WSC WG participant review and comment of wsc-xit
Last message date: Friday, 30 November 2007 19:43:51 UTC