[websec] meeting in Prague - agenda topics?

Tobias Gondrom <tobias.gondrom@gondrom.org> Thu, 10 February 2011 23:36 UTC

Return-Path: <tobias.gondrom@gondrom.org>
X-Original-To: websec@core3.amsl.com
Delivered-To: websec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 248F53A6AF7 for <websec@core3.amsl.com>; Thu, 10 Feb 2011 15:36:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -95.362
X-Spam-Level:
X-Spam-Status: No, score=-95.362 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_HELO_EQ_D_D_D_D=1.597, FH_HOST_EQ_D_D_D_D=0.765, FM_DDDD_TIMES_2=1.999, HELO_DYNAMIC_IPADDR=2.426, HELO_EQ_DE=0.35, RDNS_DYNAMIC=0.1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ktuLIdjNg+CI for <websec@core3.amsl.com>; Thu, 10 Feb 2011 15:36:53 -0800 (PST)
Received: from lvps83-169-7-107.dedicated.hosteurope.de (lvps83-169-7-107.dedicated.hosteurope.de [83.169.7.107]) by core3.amsl.com (Postfix) with ESMTP id B311F3A6A6B for <websec@ietf.org>; Thu, 10 Feb 2011 15:36:52 -0800 (PST)
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=gondrom.org; b=tfBzMQsvtbshmSV+dBZZVsx96dAyvICGzGJ8ok0cMJQH7RLYecgRxhLoJkkHHiFlEjWXeWaWzTy+FTvBu4owEycEdaQWyrteFs6LFDRBuxztcsukB9OL8vlAlUvfx8P9; h=Received:Received:Message-ID:Date:From:User-Agent:MIME-Version:To:Subject:References:In-Reply-To:X-Enigmail-Version:Content-Type:Content-Transfer-Encoding;
Received: (qmail 28563 invoked from network); 11 Feb 2011 00:36:42 +0100
Received: from unknown (HELO seraphim.heaven) (62.28.47.6) by lvps83-169-7-107.dedicated.hosteurope.de with (DHE-RSA-AES256-SHA encrypted) SMTP; 11 Feb 2011 00:36:42 +0100
Message-ID: <4D547691.1060704@gondrom.org>
Date: Thu, 10 Feb 2011 23:36:49 +0000
From: Tobias Gondrom <tobias.gondrom@gondrom.org>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.13) Gecko/20101206 SUSE/3.1.7 Lightning/1.0b2 Thunderbird/3.1.7
MIME-Version: 1.0
To: websec@ietf.org
References: <4D5470FC.1000002@stpeter.im>
In-Reply-To: <4D5470FC.1000002@stpeter.im>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Subject: [websec] meeting in Prague - agenda topics?
X-BeenThere: websec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Web Application Security Minus Authentication and Transport <websec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/websec>
List-Post: <mailto:websec@ietf.org>
List-Help: <mailto:websec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/websec>, <mailto:websec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 10 Feb 2011 23:36:54 -0000

(Thank you Peter for the reminder, I actually already scheduled a
2h-slot for Prague for websec, but seems it got stuck in the workflow
after some connectivity problems. Just did resend it again and it is
registered now.)

Dear fellow websec colleagues,

I know it's still nearly two months until Prague, but as I need to
prepare the agenda for our meeting slot in Prague, I would like to ask
you for any topics you would like to discuss.

Some topics that might come to mind:
- requirements document (we are still missing the first draft)
- mime-sniff (what do we need to progress/any controversial discussions?)
- http-headers (X-Frame-Options, ...?)
- origin
- CSP http-header
- ...?

And as a small reminder for the draft authors: the cut-off dates for
00-version is 2011-02-28 and for revised IDs it's the 2011-03-14. ;-)

I am currently at the OWASP web security summit, and there's a very
interesting browser security track, so hope to get and bring some more
input ideas from there.

Best regards and many greetings,

Tobias
(chair of websec)




On 02/10/2011 11:13 PM, Peter Saint-Andre wrote:
> I assume this working group will want to meet in Prague at IETF 80. This
> is just a reminder that the deadline for meeting requests is coming up
> soon. :)
>
> http://www.ietf.org/meeting/cutoff-dates-2011.html#IETF80
>
> Peter
>
>
>
> _______________________________________________
> websec mailing list
> websec@ietf.org
> https://www.ietf.org/mailman/listinfo/websec