[apps-discuss] Fwd: [websec] FYI: New draft draft-gondrom-frame-options-01
Tobias Gondrom <tobias.gondrom@gondrom.org> Tue, 15 March 2011 23:51 UTC
Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: apps-discuss@core3.amsl.com
Delivered-To: apps-discuss@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id A11093A6D9F for <apps-discuss@core3.amsl.com>; Tue, 15 Mar 2011 16:51:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -94.705
X-Spam-Level:
X-Spam-Status: No, score=-94.705 tagged_above=-999 required=5 tests=[AWL=-0.394, BAYES_00=-2.599, FH_HELO_EQ_D_D_D_D=1.597, FH_HOST_EQ_D_D_D_D=0.765, FM_DDDD_TIMES_2=1.999, HELO_DYNAMIC_IPADDR=2.426, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001, RDNS_DYNAMIC=0.1, SARE_TOWRITE=1.05, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W+Cbdy1e2YyW for <apps-discuss@core3.amsl.com>; Tue, 15 Mar 2011 16:51:22 -0700 (PDT)
Received: from lvps83-169-7-107.dedicated.hosteurope.de (lvps83-169-7-107.dedicated.hosteurope.de [83.169.7.107]) by core3.amsl.com (Postfix) with ESMTP id 629F43A6F03 for <apps-discuss@ietf.org>; Tue, 15 Mar 2011 16:51:20 -0700 (PDT)
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=gondrom.org; b=W5aNpmBz7Tb7oRtGKi9VPdU1fGYa+Rxm8OAg/z7wZiB8pVUJn37qGWEuwB873Qcuru4za+9x6Cg0rSCHgztgOYlxTvYG8i1AcmGQT4dXY1sU5MoQkdwELGBEZ6W7TF1q; h=Received:Received:Message-ID:Date:From:User-Agent:MIME-Version:To:Subject:X-Priority:X-Enigmail-Version:Content-Type;
Received: (qmail 15641 invoked from network); 16 Mar 2011 00:51:54 +0100
Received: from 94-194-102-93.zone8.bethere.co.uk (HELO seraphim.heaven) (94.194.102.93) by lvps83-169-7-107.dedicated.hosteurope.de with (DHE-RSA-AES256-SHA encrypted) SMTP; 16 Mar 2011 00:51:54 +0100
Message-ID: <4D7FFBDA.7070505@gondrom.org>
Date: Tue, 15 Mar 2011 23:52:58 +0000
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.14) Gecko/20110221 SUSE/3.1.8 Lightning/1.0b2 Thunderbird/3.1.8
MIME-Version: 1.0
To: apps-discuss@ietf.org
X-Priority: 4 (Low)
X-Enigmail-Version: 1.1.1
Content-Type: multipart/alternative; boundary="------------050302010402010900050701"
Subject: [apps-discuss] Fwd: [websec] FYI: New draft draft-gondrom-frame-options-01
X-BeenThere: apps-discuss@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: General discussion of application-layer protocols <apps-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/apps-discuss>
List-Post: <mailto:apps-discuss@ietf.org>
List-Help: <mailto:apps-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Mar 2011 23:51:26 -0000
Folks, just FYI as this (HTTP Header Frame-Options) may be of interest for apps area as well. - Tobias (websec) -------- Original Message -------- Subject: [websec] FYI: New draft draft-gondrom-frame-options-01 Date: Tue, 15 Mar 2011 21:43:52 +0000 From: Tobias Gondrom <tobias.gondrom@gondrom.org> To: websec@ietf.org CC: dross@microsoft.com Hello dear fellow websec colleagues, following up on some discussions at the OWASP Summit last month, David Ross and I decided to write up a draft on Frame-Options (currently know as X-Frame-Options) and to develop this further as a standard: https://datatracker.ietf.org/doc/draft-gondrom-frame-options/ The draft is still a little bit rough on the edges and e.g. how it works with websec-origin, but I hope we can sort out some of the details in Prague and with your feedback on the mailing-list. Kind regards, Tobias Ps.: and on a note as websec chair: although I believe this draft to be relevant in websec scope, I submitted it as individual draft initially, so we can have a first discussion and have a proper look for feedback whether the WG wants to adopt this draft or not. -------- Original Message -------- Subject: New Version Notification for draft-gondrom-frame-options-01 Date: Mon, 14 Mar 2011 16:19:55 -0700 (PDT) From: IETF I-D Submission Tool <idsubmission@ietf.org> To: tobias.gondrom@gondrom.org A new version of I-D, draft-gondrom-frame-options-01.txt has been successfully submitted by Tobias Gondrom and posted to the IETF repository. Filename: draft-gondrom-frame-options Revision: 01 Title: HTTP Header Frame Options Creation_date: 2011-03-15 WG ID: Independent Submission Number_of_pages: 9 Abstract: To improve the protection of web applications against Cross Site Request Forgery (CSRF) and Clickjacking this standards defines a http response header that declares a policy communicated from a host to the client browser whether the transmitted content MUST NOT be displayed in frames of other pages from different origins or a list of trusted origins which are allowed to frame the content. The IETF Secretariat.
- [apps-discuss] Fwd: [websec] FYI: New draft draft… Tobias Gondrom