Re: [websec] Websec WG meeting in Vancouver July-31 - submit agenda topics until July-21?

Tobias Gondrom <tobias.gondrom@gondrom.org> Wed, 18 July 2012 16:22 UTC

Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: websec@ietfa.amsl.com
Delivered-To: websec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E0C0421F877B for <websec@ietfa.amsl.com>; Wed, 18 Jul 2012 09:22:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -98.537
X-Spam-Level:
X-Spam-Status: No, score=-98.537 tagged_above=-999 required=5 tests=[AWL=-1.759, BAYES_00=-2.599, FH_HELO_EQ_D_D_D_D=1.597, HELO_DYNAMIC_IPADDR=2.426, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sKyYXQy34rQR for <websec@ietfa.amsl.com>; Wed, 18 Jul 2012 09:22:23 -0700 (PDT)
Received: from lvps83-169-7-107.dedicated.hosteurope.de (www.gondrom.org [83.169.7.107]) by ietfa.amsl.com (Postfix) with ESMTP id A60BE21F8714 for <websec@ietf.org>; Wed, 18 Jul 2012 09:22:22 -0700 (PDT)
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=gondrom.org; b=T5mMuSl0smlHYd25ES0U4GlTy1YzeL4o5WwHiZLBhESFtVxmh6LcrkMTPc9cogvjW76W+2EIbZ7f9FGj9lunjPTybAJ/zxK2VoEtBxJLBvTiZbkg5WFaOA2nYp8o4enE; h=Received:Received:Message-ID:Date:From:User-Agent:MIME-Version:To:CC:Subject:References:In-Reply-To:Content-Type:Content-Transfer-Encoding;
Received: (qmail 22197 invoked from network); 18 Jul 2012 18:23:08 +0200
Received: from 94-194-102-93.zone8.bethere.co.uk (HELO ?192.168.1.64?) (94.194.102.93) by www.gondrom.org with (DHE-RSA-AES256-SHA encrypted) SMTP; 18 Jul 2012 18:23:08 +0200
Message-ID: <5006E2EB.2070201@gondrom.org>
Date: Wed, 18 Jul 2012 17:23:07 +0100
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:14.0) Gecko/20120714 Thunderbird/14.0
MIME-Version: 1.0
To: bhill@paypal-inc.com
References: <4F668329.2050001@gondrom.org> <50059043.8090909@gondrom.org> <370C9BEB4DD6154FA963E2F79ADC6F2E187B94@DEN-EXDDA-S12.corp.ebay.com> <500690C9.9040806@isode.com> <370C9BEB4DD6154FA963E2F79ADC6F2E189021@DEN-EXDDA-S12.corp.ebay.com>
In-Reply-To: <370C9BEB4DD6154FA963E2F79ADC6F2E189021@DEN-EXDDA-S12.corp.ebay.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: websec@ietf.org
Subject: Re: [websec] Websec WG meeting in Vancouver July-31 - submit agenda topics until July-21?
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jul 2012 16:22:24 -0000

Hi Brad,

ah ok. Thanks for explaining. It seems I also first misunderstood your 
request. ;-)

In that light maybe two additional proposals/requests we should discuss 
before that in our websec meeting:
1. how about a quick update on WebAppSec by EKR, Jeff and/or you?

2. And then as I mentioned before, if we discuss where to put FO, maybe 
we should try to actually look at the overarching question first, 
regarding the bucket of things for CSP, asking the question which ones 
of them should be in CSP and which ones should be done individually.
And somewhat related, which ones should be done in WebAppSec and which 
ones should be done in Websec?

How about?

Best regards, Tobias


On 18/07/12 16:19, Hill, Brad wrote:
> Yes, this is the CSP vs. frame-options discussion - sorry to be oblique.
>
>> -----Original Message-----
>> From: Alexey Melnikov [mailto:alexey.melnikov@isode.com]
>> Sent: Wednesday, July 18, 2012 3:33 AM
>> To: Hill, Brad
>> Cc: Tobias Gondrom; websec@ietf.org
>> Subject: Re: [websec] Websec WG meeting in Vancouver July-31 - submit
>> agenda topics until July-21?
>>
>> On 18/07/2012 00:29, Hill, Brad wrote:
>>> Tobias,
>> Hi Brad,
>>>    I'd like to ask for some time on the agenda to discuss the future policy
>> conveyance for framing/embedding options for HTTP resources.
>> Is this related to draft-ietf-websec-frame-options-00 relationship to CSP
>> discussion, or is it a new topic?
>>> EKR and JeffH will be in Vancouver from the WebAppSec WG and I will be
>> participating remotely.
>>> Thanks,
>>>
>>> Brad Hill
>>> W3C WebAppSec WG co-chair
>>>
>>>> -----Original Message-----
>>>> From: websec-bounces@ietf.org [mailto:websec-bounces@ietf.org] On
>>>> Behalf Of Tobias Gondrom
>>>> Sent: Tuesday, July 17, 2012 9:18 AM
>>>> To: websec@ietf.org
>>>> Subject: [websec] Websec WG meeting in Vancouver July-31 - submit
>>>> agenda topics until July-21?
>>>> Importance: High
>>>>
>>>> Hi websec fellows,
>>>>
>>>> our websec meeting in Vancouver has been scheduled for Tuesday
>>>> July-31 morning 9:00-10:20 in Room "Georgia B". Very much looking
>>>> forward to meeting you all there!
>>>>
>>>> As fortunately HSTS has passed WGLC and is now in IETF LC, we will
>>>> have to opportunity to focus on new topics for websec and progress
>>>> our other work items, e.g. the frameworks requirements, cert pinning,
>> etc.
>>>> If you have a presentation topic or new topic for websec, please let
>>>> us know ASAP, so we can work on the agenda. Please, document authors
>>>> and interested presenters contact Alexey and me ASAP about your
>>>> topics and how much time you need to present.
>>>>
>>>> This time we will also have a remote presentation capability (Webex)
>>>> in addition to the audio stream and jabber, so in case you can not
>>>> make it to Vancouver, you can have a better meeting experience and
>>>> could even present remotely!
>>>>
>>>> As we are currently preparing the agenda for the websec meeting,
>>>> please submit proposals for presentations and discussions to Alexey,
>>>> Yoav and myself as soon as possible as we will have to prepare and
>>>> close the agenda for websec very soon.
>>>>
>>>> Kind regards and looking forward to our meeting in Vancouver!
>>>>
>>>> Tobias
>>>> (websec co-chair)
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> _______________________________________________
>>>> websec mailing list
>>>> websec@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/websec
>>> _______________________________________________
>>> websec mailing list
>>> websec@ietf.org
>>> https://www.ietf.org/mailman/listinfo/websec