Request for review and consensus -- draft-hartman-webauth-phishing

Lisa Dusseault <lisa@osafoundation.org> Wed, 03 September 2008 20:43 UTC

Return-Path: <ietf-http-wg-request@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@core3.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9B9DA3A6B36 for <ietfarch-httpbisa-archive-bis2Juki@core3.amsl.com>; Wed, 3 Sep 2008 13:43:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.45
X-Spam-Level:
X-Spam-Status: No, score=-8.45 tagged_above=-999 required=5 tests=[AWL=2.149, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id agc7iNpUiY37 for <ietfarch-httpbisa-archive-bis2Juki@core3.amsl.com>; Wed, 3 Sep 2008 13:43:11 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) by core3.amsl.com (Postfix) with ESMTP id 9B21A3A6A78 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Wed, 3 Sep 2008 13:43:11 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.63) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1KazBU-0006J0-Ht for ietf-http-wg-dist@listhub.w3.org; Wed, 03 Sep 2008 20:42:36 +0000
Received: from maggie.w3.org ([193.51.208.68]) by frink.w3.org with esmtp (Exim 4.63) (envelope-from <lisa@osafoundation.org>) id 1KazBL-0006IN-Lb for ietf-http-wg@listhub.w3.org; Wed, 03 Sep 2008 20:42:27 +0000
Received: from laweleka.osafoundation.org ([204.152.186.98]) by maggie.w3.org with esmtp (Exim 4.63) (envelope-from <lisa@osafoundation.org>) id 1KazBA-0006CM-VR for ietf-http-wg@w3.org; Wed, 03 Sep 2008 20:42:27 +0000
Received: from localhost (laweleka.osafoundation.org [127.0.0.1]) by laweleka.osafoundation.org (Postfix) with ESMTP id 89D5314220E; Wed, 3 Sep 2008 13:41:48 -0700 (PDT)
X-Virus-Scanned: by amavisd-new and clamav at osafoundation.org
Received: from laweleka.osafoundation.org ([127.0.0.1]) by localhost (laweleka.osafoundation.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PRmrd+r3USrU; Wed, 3 Sep 2008 13:41:38 -0700 (PDT)
Received: from [10.1.1.121] (unknown [157.22.41.236]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by laweleka.osafoundation.org (Postfix) with ESMTP id 16CC914220C; Wed, 3 Sep 2008 13:41:38 -0700 (PDT)
Message-Id: <47490048-25ED-403E-96B9-0D385F764292@osafoundation.org>
From: Lisa Dusseault <lisa@osafoundation.org>
To: HTTP Working Group <ietf-http-wg@w3.org>, secdir@mit.edu, saag@ietf.org, Apps Discuss <discuss@ietf.org>
Content-Type: text/plain; charset="US-ASCII"; format="flowed"; delsp="yes"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v928.1)
Date: Wed, 03 Sep 2008 13:41:39 -0700
Cc: ietf-http-auth@osafoundation.org
X-Mailer: Apple Mail (2.928.1)
Received-SPF: pass
X-SPF-Guess: pass
X-W3C-Hub-Spam-Status: No, score=-6.6
X-W3C-Hub-Spam-Report: BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, SPF_PASS=-0.001
X-W3C-Scan-Sig: maggie.w3.org 1KazBA-0006CM-VR 1f1e448eb92d748e16346d466567782e
X-Original-To: ietf-http-wg@w3.org
Subject: Request for review and consensus -- draft-hartman-webauth-phishing
Archived-At: <http://www.w3.org/mid/47490048-25ED-403E-96B9-0D385F764292@osafoundation.org>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/5260
X-Loop: ietf-http-wg@w3.org
Sender: ietf-http-wg-request@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
Resent-Message-Id: <E1KazBU-0006J0-Ht@frink.w3.org>
Resent-Date: Wed, 03 Sep 2008 20:42:36 +0000


You may have seen this draft a year ago; Sam is back working on it and  
produced version -09 last month.

http://tools.ietf.org/html/draft-hartman-webauth-phishing-09

If you've reviewed it before, please take a look at the changes.  If  
you'd like to review it, please do.  I'm the shepherd for this draft,  
so comments can be sent to me, to Sam as author, to ietf-http-auth@osafoundation.org 
, or to the IETF general list as appropriate.

In addition to getting general input, I'd like to get a sense of  
whether we have consensus on a couple things.

a).  The statement including "IETF recommends", from section 1.1 of  
the draft:

    "In publishing this memo, the IETF recommends making available
    authentication mechanisms that meet the requirements outlined in
    Section 4 in HTTP user agents including web browsers.  It is hoped
    that these mechanisms will prove a useful step in fighting phishing.
    However this memo does not restrict work either in the IETF or any
    other organization.  In particular, new authentication efforts are
    not bound to meet the requirements posed in this memo unless the
    charter for those efforts chooses to make these binding  
requirements.
    Less formally, the IETF presents this memo as an option to pursue
    while acknowledging that there may be other promising paths both now
    and in the future."

b) Whether the document should require mutual authentication (section  
4.4).

Thanks,
Lisa D.