ACTION-1 |
closed |
Link tracker from Group page |
Thomas Roessler |
2006-11-21 |
|
ACTION-2 |
closed |
Organize call with APWG to discuss liaison mechanisms with WSCWG |
Thomas Roessler |
2007-01-24 |
|
ACTION-3 |
closed |
Contribute use cases for Note |
Stephen Farrell |
2006-11-21 |
|
ACTION-4 |
closed |
Formalize the scenario of user getting a request via e-mail and using that information to contact a web-site using HTTP protocol (e.g. using a browser) |
Phillip Hallam-Baker |
2006-11-21 |
|
ACTION-5 |
closed |
Formalize the use case of mis-typing a URL (and various variants - been there before, not been there before) |
Mary Ellen Zurko |
2006-12-08 |
|
ACTION-6 |
closed |
Formalize the statement regarding users not relying on information within URL strings for establishing context (or security context) |
Tyler Close |
2006-11-21 |
|
ACTION-7 |
closed |
Work out impact of redirection scenarios |
Hal Lockhart |
2006-11-21 |
|
ACTION-8 |
closed |
Formalize use case around user contacting one site, then getting re-directed to another (as part of a federation of organziations working together, legitimately), how does the user trust where they landed on? |
Hal Lockhart |
2006-11-21 |
|
ACTION-9 |
closed |
Formalize the use case of content providers using the same icons as are typically used in the \"chrome area\" and thus diluting the meaning of such visual aids |
Michael Smith |
2006-11-21 |
|
ACTION-10 |
closed |
Find mobile browser vendors to recruit to group |
Michael Smith |
2006-11-21 |
|
ACTION-11 |
closed |
Formalize a use case for using a browser on a shared device (e.g. kiosk device). Examples of kiosks intra-enterprise, hotel lobbies, Kinko\\\\\\\\\'s, libraries. |
Hal Lockhart |
2006-12-19 |
|
ACTION-12 |
closed |
List, by enumeration, what is meant by security context information |
Hal Lockhart |
2006-11-21 |
|
ACTION-13 |
closed |
Elaborate on multiple certificates & domains for session servers case |
Tyler Close |
2006-11-21 |
|
ACTION-14 |
closed |
Write up use case of session servers and having critical information invariant in order to be useful. |
Hal Lockhart |
2006-11-21 |
|
ACTION-15 |
closed |
Produce use case story for kiosk case that is in scope (action can be discharged by declaring defeat) |
Mary Ellen Zurko |
2006-12-08 |
|
ACTION-16 |
closed |
Formalize the use case of flowing security information as a part of the document mark up (as in XML marked up content information). |
Yakov Sverdlov |
2006-12-01 |
|
ACTION-17 |
closed |
Give a demonstration of \"pet name\" annotation of bookmarks plug-in |
Tyler Close |
2007-01-31 |
|
ACTION-18 |
closed |
Formalize the need to be able to understand/visualize the \"strength\" of SSL protection in place |
Bill Doyle |
2006-11-21 |
|
ACTION-19 |
closed |
Formalize a user-facing use case for WS-Security (e.g. use of WS-SecureConversation) |
Tim Hahn |
2006-12-01 |
|
ACTION-20 |
closed |
Put together set of background references |
Mary Ellen Zurko |
2006-12-01 |
|
ACTION-21 |
closed |
Help MEZ with ACTION-20 |
Maritza Johnson |
2006-12-01 |
|
ACTION-22 |
closed |
Produce voice browser use case |
Brandon Porter |
2006-11-22 |
|
ACTION-23 |
closed |
Find out more about Opera\\\\\'s numeric trust indicator |
Michael Smith |
2006-11-22 |
|
ACTION-24 |
closed |
Set up Wiki for group use |
Thomas Roessler |
2006-11-22 |
|
ACTION-25 |
closed |
Set up CVS access for Tyler |
Thomas Roessler |
2006-11-22 |
|
ACTION-26 |
closed |
Dig out papers about authenticating browser password entry dialogues to users |
Mary Ellen Zurko |
2006-12-08 |
|
ACTION-27 |
closed |
review requirements from workshop record |
Hal Lockhart |
2007-01-26 |
|
ACTION-28 |
closed |
Clean up minutes |
Thomas Roessler |
2006-11-22 |
|
ACTION-29 |
closed |
Rob Franco to formalize the use case of an attacker messing with the information in the address bar and confusing the user. |
Thomas Roessler |
2006-12-12 |
|
ACTION-30 |
closed |
Find collection of known anti-phishing extensions for Firefox |
Tyler Close |
2006-11-21 |
|
ACTION-31 |
closed |
Skeletal draft of Note |
Tyler Close |
2006-11-20 |
|
ACTION-32 |
closed |
Come up with a use case for FTP\\\\\'s usage |
Stephen Farrell |
2006-11-28 |
|
ACTION-33 |
closed |
Draft goals / non-goals section |
Phillip Hallam-Baker |
2006-12-07 |
|
ACTION-34 |
closed |
Draft scope/out-of-scope |
Mary Ellen Zurko |
2006-11-28 |
|
ACTION-35 |
closed |
Open issue for xpath/xquery in/out-of scope |
Thomas Roessler |
2006-11-28 |
|
ACTION-36 |
closed |
Add note\\\\\'s structure to wiki |
Tyler Close |
2006-12-12 |
|
ACTION-37 |
closed |
Review widget spec |
Thomas Roessler |
2006-12-12 |
|
ACTION-38 |
closed |
Include trusted computing base with scope and/or goals/non-goals |
Mary Ellen Zurko |
2006-12-12 |
|
ACTION-39 |
closed |
Training users to rely on specific non-ubiquitous security context |
Maritza Johnson |
2006-12-12 |
|
ACTION-40 |
closed |
Send proposed language on phones to mailing lists |
Phillip Hallam-Baker |
2006-12-19 |
|
ACTION-41 |
closed |
Propose draft language |
Mike Beltzner |
2006-12-19 |
|
ACTION-42 |
closed |
Propose draft language to capture \"how to begin secure communication\" |
Mike Beltzner |
2006-12-19 |
|
ACTION-43 |
closed |
Review this use case |
Tyler Close |
2006-12-19 |
|
ACTION-44 |
closed |
Review DesktopDecoration |
Tyler Close |
2006-12-19 |
|
ACTION-45 |
closed |
Work with beltzner on ACTION-42 to possibly broaden it |
Thomas Roessler |
2006-12-19 |
|
ACTION-46 |
closed |
Add in-scope for appropriateness of communication of security context information |
Thomas Roessler |
2006-12-19 |
|
ACTION-47 |
closed |
Yank \"not dangerous\" from out-of-scope |
Mary Ellen Zurko |
2006-12-19 |
|
ACTION-48 |
closed |
Propose revised \"non-web protocols\" text for NoteOutOfScope |
Stephen Farrell |
2006-12-19 |
|
ACTION-49 |
closed |
Amend in-scope to reflect consistency of user experiences, warning levels, etc |
Mike Beltzner |
2006-12-19 |
|
ACTION-50 |
closed |
Add mobile device text to scope text in wiki |
Stephen Farrell |
2006-12-20 |
|
ACTION-51 |
closed |
Draft \"out-of-scope\" text for proxies etc that do not involve human interaction |
Stephen Farrell |
2006-12-26 |
|
ACTION-52 |
closed |
Propose text on how corroboration with independent sites should be scoped |
Tim Hahn |
2006-12-26 |
|
ACTION-53 |
closed |
Edit out content blocking part |
Hal Lockhart |
2006-12-26 |
|
ACTION-54 |
closed |
Write concrete \"content blocking out of scope\" section, or to declare defeat |
Anthony Nadalin |
2006-12-26 |
|
ACTION-55 |
closed |
Merge the TCB-related points |
Tyler Close |
2006-12-26 |
|
ACTION-56 |
closed |
Drive discussion on presentation of content-based filtering on list, draft text |
Hal Lockhart |
2006-12-26 |
|
ACTION-57 |
closed |
Maintain volunteer list in NoteIndex in the wiki. |
Mary Ellen Zurko |
2006-12-26 |
|
ACTION-58 |
closed |
Draft the \"Security Context Available\" section of our Note in the wiki |
Bill Doyle |
2007-01-02 |
|
ACTION-59 |
closed |
Draft section 9 |
Tim Hahn |
2007-01-02 |
|
ACTION-60 |
closed |
Draft Section 8 |
Michael Smith |
2007-01-02 |
|
ACTION-61 |
closed |
Propose re-wording of \"Best Practices Recommendation for Site-to-User Communication\" text in NoteGoals, post to list |
Mary Ellen Zurko |
2007-01-09 |
|
ACTION-62 |
closed |
Re-draft \"Recommendation for Consistent Presentation of Security Information\" to reflect discussion about http://www.w3.org/mid/D0C847B2BD75414090045D8C7EA3D59402E1469E@repbex01.amer.bea.com |
Hal Lockhart |
2007-01-09 |
|
ACTION-63 |
closed |
Merge the Goals and Non-Goals related Wiki items into English text. |
Phillip Hallam-Baker |
2007-01-23 |
|
ACTION-64 |
closed |
Make sure role of user education is addressed in assumptions section of note |
Mary Ellen Zurko |
2007-01-09 |
|
ACTION-65 |
closed |
Add \"phone\" option to registration form, and fix some responses |
Thomas Roessler |
2007-01-09 |
|
ACTION-66 |
closed |
Rework shared system use-case |
Hal Lockhart |
2007-01-16 |
|
ACTION-67 |
closed |
Refine MultipleCertificateIdentity use case |
Tyler Close |
2007-01-16 |
|
ACTION-68 |
closed |
Formalize furnace self-signed use case |
Tyler Close |
2007-01-16 |
|
ACTION-69 |
closed |
Draft differential use cases for security expectation vs. none |
Phillip Hallam-Baker |
2007-01-29 |
|
ACTION-70 |
closed |
Propose generalization of email lure |
Stuart Schechter |
2007-01-16 |
|
ACTION-71 |
closed |
Propose history related use-case |
Stephen Farrell |
2007-01-16 |
|
ACTION-72 |
closed |
Track RobFranco proposing use cases to deal with scriptable areas |
Thomas Roessler |
2007-02-28 |
|
ACTION-73 |
closed |
Draft MITM use case |
Thomas Roessler |
2007-01-16 |
|
ACTION-74 |
closed |
Draft CA acceptance use case |
Thomas Roessler |
2007-01-16 |
|
ACTION-75 |
closed |
Draft revisit security decisions use case |
Thomas Roessler |
2007-01-16 |
|
ACTION-76 |
closed |
Draft follow-a-link / status bar use case |
Thomas Roessler |
2007-01-16 |
|
ACTION-77 |
closed |
Design Debugging use case |
Mary Ellen Zurko |
2007-01-16 |
|
ACTION-78 |
closed |
Refine UserNotions |
Michael McCormick |
2007-01-16 |
|
ACTION-79 |
closed |
Redraft out-of-scope item for phone |
Brandon Porter |
2007-01-23 |
|
ACTION-80 |
closed |
Redraft phonelure use case |
Phillip Hallam-Baker |
2007-01-23 |
|
ACTION-81 |
closed |
Follow up on the FollowingALink use case |
Thomas Roessler |
2007-01-23 |
|
ACTION-82 |
closed |
Document widget behavior upon encountering a link in wiki |
Thomas Roessler |
2007-01-29 |
|
ACTION-83 |
closed |
Dig out TLS RFC\\\\\'s normative language on mismatch between cert and domain name |
Hal Lockhart |
2007-01-30 |
|
ACTION-84 |
closed |
Produce material on name-based virtual hosting and TLS |
Phillip Hallam-Baker |
2007-01-30 |
|
ACTION-85 |
closed |
Summarize issues around deployment of certificates in wildcard / virtual hosting situations |
Chuck Wade |
2007-01-30 |
|
ACTION-86 |
closed |
Document what certificate validation errors Konqueror displays |
George Staikos |
2007-01-30 |
|
ACTION-87 |
closed |
Document what certificate validation errors Opera displays |
Yngve Pettersen |
2007-01-30 |
|
ACTION-88 |
closed |
Document what certificate validation errors Firefox displays |
Mike Beltzner |
2007-01-30 |
|
ACTION-89 |
closed |
Ask Rob to do the same for IE7 |
Thomas Roessler |
2007-01-30 |
|
ACTION-90 |
closed |
Ask Rob Franco to document what certification verification errors IE7 displays |
Thomas Roessler |
2007-02-28 |
|
ACTION-91 |
closed |
Start discussion about RevistingPastDecision on list |
Thomas Roessler |
2007-01-30 |
|
ACTION-92 |
closed |
Send more detailed geography info about meeting to member-visible list |
Hal Lockhart |
2007-01-30 |
|
ACTION-93 |
closed |
Explain issue raising process on public mailing list |
Thomas Roessler |
2007-02-06 |
|
ACTION-94 |
closed |
Draft subsections for 8 about \"compelling user interface\", crypto |
Phillip Hallam-Baker |
2007-02-06 |
|
ACTION-95 |
closed |
Review use cases, suggest reorganization, ... |
Stuart Schechter |
2007-03-10 |
|
ACTION-96 |
closed |
Draft initial outline of glossary |
Tim Hahn |
2007-02-21 |
|
ACTION-97 |
closed |
Seed and drive process to document current-generation undocumented safeguards in wiki |
Mike Beltzner |
2007-02-17 |
|
ACTION-98 |
closed |
Add references for 8.1.2 |
Rachna Dhamija |
2007-02-06 |
|
ACTION-99 |
closed |
draft text for section 8, covering \"block pages\" |
Rachna Dhamija |
2007-02-06 |
|
ACTION-100 |
closed |
Propose alternative wording for 8.2.3 |
Thomas Roessler |
2007-02-06 |
|
ACTION-101 |
closed |
Suggest favorite favicon reference |
Mary Ellen Zurko |
2007-02-06 |
|
ACTION-102 |
closed |
Switch order of 8.2.3 and 8.2.4 |
Tyler Close |
2007-02-06 |
|
ACTION-103 |
closed |
Propose descriptive text on firefox anti-phishing UI (for 8.2) |
Mike Beltzner |
2007-02-17 |
|
ACTION-104 |
closed |
Extend 8.2.1 by tab title |
Tyler Close |
2007-02-06 |
|
ACTION-105 |
closed |
Propose text on notifiaction / information bar |
Mike Beltzner |
2007-02-17 |
|
ACTION-106 |
closed |
Propose clarifying language for 8.2.5 |
Mike Beltzner |
2007-02-17 |
|
ACTION-107 |
closed |
Create a library of testcases / examples of attacks listed in section 8 |
Mike Beltzner |
2007-02-22 |
|
ACTION-108 |
closed |
contribute more studies for 8.3 |
Rachna Dhamija |
2007-02-06 |
|
ACTION-109 |
closed |
to propose more elaborate text for 8.3.1 (\"padlock icon\") |
Brandon Porter |
2007-02-06 |
|
ACTION-110 |
closed |
Create new subsection under 8.2 to classify types of attacks |
Tyler Close |
2007-02-06 |
|
ACTION-111 |
closed |
Track rob tracking URL scrolling issues |
Tyler Close |
2007-02-06 |
|
ACTION-112 |
closed |
Rewrite 8.3.2 |
Thomas Roessler |
2007-02-06 |
|
ACTION-113 |
closed |
Suggest \"page\" definition for Tim\\\\\\\\\'s glossary |
Stuart Schechter |
2007-03-12 |
|
ACTION-114 |
closed |
suggesting alternative wording for 8.4.1 |
Rachna Dhamija |
2007-02-06 |
|
ACTION-115 |
closed |
Contribute reference on cost/benefit questions in usability |
Mary Ellen Zurko |
2007-02-07 |
|
ACTION-116 |
closed |
Check whether security usability of form submission is covered in Note |
Phillip Hallam-Baker |
2007-02-07 |
|
ACTION-117 |
closed |
Contribute material re confirmation bias to note |
Mike Beltzner |
2007-02-17 |
|
ACTION-118 |
closed |
Reword the first two DesignPrinciples points for possible inclusion in the note |
Maritza Johnson |
2007-02-16 |
|
ACTION-119 |
closed |
Move consistency bullet point into section 9 |
Tyler Close |
2007-02-07 |
|
ACTION-120 |
closed |
Contribute further text on \"explanations\" bullet point; provide [Patrick] reference |
Maritza Johnson |
2007-02-16 |
|
ACTION-121 |
closed |
Propose rewrite of 9.3 |
Mary Ellen Zurko |
2007-02-07 |
|
ACTION-122 |
closed |
Inquire Stephen Farrell about holding next meeting on 30-31 in Dublin |
Thomas Roessler |
2007-02-07 |
|
ACTION-123 |
closed |
Send hosting requirements to Tyler |
Thomas Roessler |
2007-02-07 |
|
ACTION-124 |
closed |
Initiate work on threat tree |
Stuart Schechter |
2007-03-13 |
|
ACTION-125 |
closed |
Map list from blackboard to existing use cases, possibly add more |
Thomas Roessler |
2007-02-08 |
|
ACTION-126 |
closed |
Document current practice in terms of security UI robustness |
George Staikos |
2007-02-28 |
|
ACTION-127 |
closed |
Document current practice in terms of security UI robustness |
Yngve Pettersen |
2007-02-08 |
|
ACTION-128 |
closed |
Document current practice in terms of security UI robustness |
Mike Beltzner |
2007-02-17 |
|
ACTION-129 |
closed |
Prod Rob to document current practice in terms of security UI robustness |
Thomas Roessler |
2007-02-28 |
|
ACTION-130 |
closed |
Set up poll to confirm date. |
Thomas Roessler |
2007-02-08 |
|
ACTION-131 |
closed |
Start rescheduling exercise for telephone calls |
Thomas Roessler |
2007-02-19 |
|
ACTION-132 |
closed |
Start discussion on mailing list to draw chrome items out and get analysis completed |
Mary Ellen Zurko |
2007-02-13 |
|
ACTION-133 |
closed |
Offer text suggestion around \"many users\" |
Brandon Porter |
2007-02-13 |
|
ACTION-134 |
closed |
Link scribing quick-ref from WG admin page |
Thomas Roessler |
2007-02-13 |
|
ACTION-135 |
closed |
Reword 2.2 a bit more verbosely; add negative (\"not stuff that\\\\\'s easily ignored\") |
Tyler Close |
2007-02-13 |
|
ACTION-136 |
closed |
S/prevent/mitigate and prevent/ in 2.3 |
Tyler Close |
2007-02-13 |
|
ACTION-137 |
closed |
S/deceptive imitation/deceptive imitation or hiding/ in 2.3 |
Tyler Close |
2007-02-13 |
|
ACTION-138 |
closed |
Re-phrase Thomas\\\\\'s proposed overview text. |
Mary Ellen Zurko |
2007-02-13 |
|
ACTION-139 |
closed |
Reorder section 2: 2.7, 2.4, then rest |
Tyler Close |
2007-02-13 |
|
ACTION-140 |
closed |
Propose non-goals material re other app contexts |
Hal Lockhart |
2007-02-20 |
|
ACTION-141 |
closed |
Replace \"orthogonal\" by clearer language in the use case rework |
Thomas Roessler |
2007-02-20 |
|
ACTION-142 |
closed |
Change use case 19 to make clear that network-levle confdentiality threats are covered |
Thomas Roessler |
2007-02-20 |
|
ACTION-143 |
closed |
Propose text to resolve ISSUE-10 |
Thomas Roessler |
2007-02-20 |
|
ACTION-144 |
closed |
Drop public sample code promise from 10.3 and send text to list & tyler |
Mary Ellen Zurko |
2007-02-20 |
|
ACTION-145 |
closed |
Expand abstract of note by moving in material from overview |
Thomas Roessler |
2007-02-27 |
|
ACTION-146 |
closed |
Start conversation on conformance for non-browser user agents and forward-looking web use |
Chuck Wade |
2007-02-27 |
|
ACTION-147 |
closed |
Send reminder concerning out-of-order US DST change |
Mary Ellen Zurko |
2007-03-13 |
|
ACTION-148 |
closed |
Start discussion on technology-layer security context |
Johnathan Nightingale |
2007-03-13 |
|
ACTION-149 |
closed |
Make FSTC\\\\\'s list of techniques available to group |
Chuck Wade |
2007-03-13 |
|
ACTION-150 |
closed |
Propose text do drill down on possible classes of conforming implementations -- more concrete than note, more abstract than products |
Chuck Wade |
2007-04-15 |
|
ACTION-151 |
closed |
update text for security context as part of note review |
Bill Doyle |
2007-03-16 |
|
ACTION-152 |
closed |
Put Tim Hahn\\\\\'s outline into Wiki, fill in some, |
Stuart Schechter |
2007-03-20 |
|
ACTION-153 |
closed |
Tell tyler about how to do diffs for specprod documents |
Thomas Roessler |
2007-03-20 |
|
ACTION-154 |
closed |
Track HTTP Auth related extensions |
Bill Doyle |
2007-03-20 |
|
ACTION-155 |
closed |
Track P3P header related indicators |
Praveen Alavilli |
2007-03-28 |
|
ACTION-156 |
closed |
Circulate his list of privacy and security indicators |
Chuck Wade |
2007-03-20 |
|
ACTION-157 |
closed |
Update 7.2 to encompass page source |
Tyler Close |
2007-03-28 |
|
ACTION-158 |
closed |
Add documentation of known systemic flaws to \"Document the status quo\" goal |
Thomas Roessler |
2007-03-20 |
|
ACTION-159 |
closed |
Put documentation about action item editing interface on group page |
Thomas Roessler |
2007-04-25 |
|
ACTION-160 |
closed |
Put out-of-scope text on cross-site-scripting into Note |
Tyler Close |
2007-03-27 |
|
ACTION-161 |
closed |
Send note to chuck on prior art re ACTION-150 |
Thomas Roessler |
2007-03-27 |
|
ACTION-162 |
closed |
Draft \"sensitive piece of information\" proposal |
Tyler Close |
2007-03-28 |
|
ACTION-163 |
closed |
to draft \"where am I\" outline |
Rachna Dhamija |
2007-04-30 |
|
ACTION-164 |
closed |
elaborate cross-site-scripting branch of threat tree with view toward user understandable context information |
Johnathan Nightingale |
2007-03-28 |
|
ACTION-165 |
closed |
Copy definition of web user agent to glossary |
Mary Ellen Zurko |
2007-03-27 |
|
ACTION-166 |
closed |
Set up shawn and rachna as additional editors |
Thomas Roessler |
2007-04-04 |
|
ACTION-167 |
closed |
to send mail to outline quick review process for further April calls; call for agenda input for next call |
Mary Ellen Zurko |
2007-04-04 |
|
ACTION-168 |
closed |
really cancel May 9 call |
Mary Ellen Zurko |
2007-05-02 |
|
ACTION-169 |
closed |
Put roadmap into wiki |
Mary Ellen Zurko |
2007-04-04 |
|
ACTION-170 |
closed |
Put 4th f2f on Dublin agenda: September or November? |
Mary Ellen Zurko |
2007-05-04 |
|
ACTION-171 |
closed |
And stuart to try to figure out how to move forward with this |
Thomas Roessler |
2007-04-04 |
|
ACTION-172 |
closed |
Map threat trees to use case dimensions |
Stuart Schechter |
2007-04-04 |
|
ACTION-173 |
closed |
Turn use case dimensions into note material |
Thomas Roessler |
2007-06-08 |
|
ACTION-174 |
closed |
Send mail to outline quick review process for further April calls; call for agenda input for next call |
Mary Ellen Zurko |
2007-04-04 |
|
ACTION-175 |
closed |
Summarize robustness practices in terms of limitations on sites\\\\\\\\\\\\\\\\\' freedom |
Johnathan Nightingale |
2007-04-25 |
|
ACTION-176 |
closed |
Ping george staikos by e-mail and negotiate corresponding action |
Thomas Roessler |
2007-04-11 |
|
ACTION-177 |
closed |
aggregate material on TLS user interaces across browsers, based on input from vendors |
Mike Beltzner |
2007-04-25 |
|
ACTION-178 |
closed |
pull together mixed content / \"what is a secure page\" material from earlier list discussions |
Yngve Pettersen |
2007-04-25 |
|
ACTION-179 |
closed |
put check of recommendation material against InScopbyCategory wiki item on f2f agenda; find volunteer to lead that discussion |
Mary Ellen Zurko |
2007-05-15 |
|
ACTION-180 |
closed |
Make pass through SharedBookmarks and other material; map testing results to status quo |
Maritza Johnson |
2007-05-08 |
|
ACTION-181 |
closed |
summarize EV cert discussion and deliver proto recommendations in Wiki |
Phillip Hallam-Baker |
2007-04-18 |
|
|