[websec] agenda for Beijing: topics and presentation ideas?

Tobias Gondrom <tobias.gondrom@gondrom.org> Sun, 24 October 2010 17:05 UTC

Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: websec@core3.amsl.com
Delivered-To: websec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id B6C4C3A68FC for <websec@core3.amsl.com>; Sun, 24 Oct 2010 10:05:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -94.588
X-Spam-Level:
X-Spam-Status: No, score=-94.588 tagged_above=-999 required=5 tests=[AWL=0.174, BAYES_00=-2.599, FH_HELO_EQ_D_D_D_D=1.597, FH_HOST_EQ_D_D_D_D=0.765, FM_DDDD_TIMES_2=1.999, HELO_DYNAMIC_IPADDR=2.426, HELO_EQ_DE=0.35, J_CHICKENPOX_12=0.6, RDNS_DYNAMIC=0.1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zw2cYTJvtjmr for <websec@core3.amsl.com>; Sun, 24 Oct 2010 10:05:45 -0700 (PDT)
Received: from lvps83-169-7-107.dedicated.hosteurope.de (lvps83-169-7-107.dedicated.hosteurope.de [83.169.7.107]) by core3.amsl.com (Postfix) with ESMTP id 0D5B33A66B4 for <websec@ietf.org>; Sun, 24 Oct 2010 10:05:44 -0700 (PDT)
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=gondrom.org; b=YJ1w2z3AkAPvYyAp9v3I7jnvvmHfpsP6DXcTWIRNrKEr5IbbKp99PJseVqbTF0zuFIrOSlbTavsLHEAwxHNPyI+l7kFQlaowgbp90nVc1VikkTJVULJe1Ezzn2tdN0kL; h=Received:Received:Message-ID:Date:From:User-Agent:MIME-Version:To:Subject:X-Priority:X-Enigmail-Version:Content-Type:Content-Transfer-Encoding;
Received: (qmail 32346 invoked from network); 24 Oct 2010 19:06:40 +0200
Received: from 94-194-102-93.zone8.bethere.co.uk (HELO seraphim.heaven) (94.194.102.93) by lvps83-169-7-107.dedicated.hosteurope.de with (DHE-RSA-AES256-SHA encrypted) SMTP; 24 Oct 2010 19:06:40 +0200
Message-ID: <4CC467AD.8090408@gondrom.org>
Date: Sun, 24 Oct 2010 18:06:53 +0100
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.9) Gecko/20100914 SUSE/3.1.4 Lightning/1.0b2 Thunderbird/3.1.4
MIME-Version: 1.0
To: websec@ietf.org
X-Priority: 2 (High)
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Subject: [websec] agenda for Beijing: topics and presentation ideas?
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 24 Oct 2010 17:05:46 -0000

 Hello dear fellow websec members,

am currently working on the agenda for our meeting in Beijing.
we have a session on Tuesday Nov-9, 1300-1500 (Afternoon Session)

Please send proposals for presentations or agenda items to me or to the
list ASAP!

>From the past discussions on the list I could see there are a lot of
topics to discuss:
1. requirements doc: please we still need at least a straw-man as basis
for discussion - any volunteers please???
maybe s.th. based on Jeff and Andy's whitepaper
(http://w2spconf.com/2010/papers/p11.pdf)
2. progress and discussion on
- Origin: draft-abarth-mime-sniff
- Media-Type Sniffing: draft-abarth-origin
- Strict Transport Security: draft-hodges-strict-transport-sec
(btw. if you haven't read the IDs yet, maybe now a good time to read
them and post feedback on the list)
4. usage of DNSSEC for strict sec?
5. integrity of the browser and server?
6. overall framework: are there ideas how to fit our various points into
an overarching concept? Any proposals, straw-man presentations -
volunteers please?
7. X-FRAME-OPTIONS (or better FRAME-OPTIONS http header): any volunteer
to throw a proposal in the ring?
8... ?

Kind regards and please volunteers contact me ASAP (email, phone)!
(I think we can also arrange for remote presentation facility using
webex, if a presenter can't make it to Beijing.)

Tobias


Tobias Gondrom
email: tobias.gondrom@gondrom.org
mobile: +447521003005