13:47:20 RRSAgent has joined #dap 13:47:20 logging to http://www.w3.org/2010/10/06-dap-irc 13:47:22 RRSAgent, make logs world 13:47:22 Zakim has joined #dap 13:47:24 Zakim, this will be DAP 13:47:24 ok, trackbot; I see UW_DAP()10:00AM scheduled to start in 13 minutes 13:47:25 Meeting: Device APIs and Policy Working Group Teleconference 13:47:25 Date: 06 October 2010 13:48:04 Chair: Robin_Berjon, Frederick_Hirsch 13:48:14 Present+ Robin_Berjon, Frederick_Hirsch 13:48:44 Agenda: http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0007.html 13:49:04 DAP 3279 ; agenda http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0007.html ; Please register Present+ First_Last; also update zakim handle, zakim, aaa is handle 13:50:38 Regrets+ Marco_Marengo, Suresh_Chitturi 13:51:57 Regrets+ Dominique-Hazael-Massieux 13:53:08 Topic: Administrative 13:58:17 UW_DAP()10:00AM has now started 13:58:24 +[IPcaller] 13:58:39 zakim, [IPcaller] is me 13:58:39 +fjh; got it 13:59:43 Claes has joined #dap 13:59:56 +[IPcaller] 13:59:59 fjh: sorry, no 13:59:59 arve has left #dap 14:00:28 AnssiK has joined #dap 14:00:30 LauraA has joined #dap 14:00:51 Zakim, code? 14:00:51 the conference code is 3279 (tel:+1.617.761.6200 tel:+33.4.26.46.79.03 tel:+44.203.318.0479), dom 14:00:52 zakim, [IPcaller] is wonsun 14:00:53 +wonsun; got it 14:00:59 +??P4 14:01:09 Present+ Dominique_Hazael-Massieux 14:01:10 +Dom (was ??P4) 14:01:20 Zakim, why won't you return my calls anymore? 14:01:20 I don't understand your question, darobin. 14:01:23 Regrets- Dominique-Hazael-Massieux 14:01:25 + +46.1.08.01.aaaa 14:01:27 Present+ LauraA 14:01:29 Dong-Young has joined #dap 14:01:48 Present+ Dong-Young_Lee 14:02:01 Zakim, aaaa is Claes 14:02:01 +Claes; got it 14:02:10 +??P7 14:02:17 Present+ Claes_Nilsson 14:02:23 + +44.777.541.aabb 14:02:29 Zakim, ??P7 is me 14:02:29 +darobin; got it 14:02:32 + +44.757.091.aacc 14:02:36 Zakim, aabb is LauraA 14:02:37 +LauraA; got it 14:02:56 zakim, wonsun is wonsuk 14:02:56 +wonsuk; got it 14:03:02 Zakim, aacc is me 14:03:02 +richt; got it 14:03:05 Present+ Wonsuk_Lee 14:03:09 zakim, who is here? 14:03:09 On the phone I see fjh, wonsuk, Dom, Claes, darobin, LauraA, richt 14:03:11 On IRC I see Dong-Young, LauraA, AnssiK, Claes, Zakim, RRSAgent, fjh, darobin, richt, wmaslowski, shepazu, trackbot, ingmar, ilkka, dom 14:03:11 Present+ Richard_Tibbett 14:04:02 + +358.504.86aadd 14:04:05 Present+ Anssi_Kostiainen 14:04:12 nwidell has joined #dap 14:04:13 zakim, aadd is AnssiK 14:04:13 +AnssiK; got it 14:04:57 + +358.504.86aaee 14:05:05 Scribenick: Claes 14:05:16 zakim, aaee is ilkka 14:05:16 +ilkka; got it 14:05:24 + +46.1.07.15.aaff 14:05:26 Present+ Ilkka_Oksanen 14:05:29 WG questionnaire (for all), http://www.w3.org/2002/09/wbs/43696/tpac2010dap/ 14:05:30 TPAC registration (for in-person attendees) http://www.w3.org/2002/09/wbs/35125/TPAC2010reg/ 14:05:44 Topic: TPAC registration 14:05:46 zakim, aaff is nwidell 14:05:46 +nwidell; got it 14:05:48 cmarc has joined #dap 14:05:54 Reminder for everyone to register 14:06:04 Present+ Niklas_Widell 14:06:54 Agenda: ; Please register Present+ First_Last; also update zakim handle, zakim, aaa is handle 14:07:05 Agenda: http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0007.html 14:07:13 Present Cecile_Marc 14:07:18 "Permissions for Device API Access" published as First Public Working Draft, , http://w3.org/TR/api-perms 14:07:27 Reminder, no call next week (13 October 2010 Teleconference Cancelled) 14:07:32 Reminder, no call next week 14:07:38 Next teleconference 20 October, http://www.w3.org/2009/dap/minutes 14:07:54 Topic: Minutes approval 14:07:57 http://lists.w3.org/Archives/Public/public-device-apis/2010Sep/att-0160/minutes-2010-09-29.html 14:08:05 proposed RESOLUTION: Minutes from 29 Sept 2010 approved 14:08:05 ] 14:08:19 RESOLUTION: Minutes from 29 Sept 2010 approved 14:08:32 Topic: Permissions 14:08:37 +Vincent_Mahe 14:08:44 Draft published 14:08:47 published, http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0006.html 14:09:06 Zakim, Vincent_Mahe is CecileMarc 14:09:06 +CecileMarc; got it 14:09:07 Zakim, Vincent_Mahe is really Cecile_Marc 14:09:07 sorry, dom, I do not recognize a party named 'Vincent_Mahe' 14:09:19 Present+ Cecile_Marc 14:09:23 + +1.425.214.aagg 14:09:27 Zakim, CecileMarc is cmarc 14:09:27 +cmarc; got it 14:09:33 bryan has joined #dap 14:09:56 welcome cecile! 14:10:10 Present+ Bryan_Sullivan 14:10:12 New member: Cecile Mark, Orange 14:10:20 s/Mark/Marc/ 14:10:27 Topic: Privacy 14:10:48 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0008.html 14:10:55 Alissa added issues to draft 14:11:11 ACTION-210? 14:11:11 ACTION-210 -- Alissa Cooper to summarize and add issues to ruleset doc -- due 2010-07-21 -- OPEN 14:11:11 http://www.w3.org/2009/dap/track/actions/210 14:11:31 W3C Workshop on Privacy and data usage control held 4-5 October, http://www.w3.org/2010/policy-ws/agenda.html 14:11:38 Workshop in Boston 14:11:59 jmorris has joined #dap 14:12:18 12http://www.w3.org/2010/policy-ws/papers/03-Doty-Wilde-Berkeley.pdf 14:12:18 12http://www.w3.org/2010/09/raggett-fresh-take-on-p3p/ 14:12:19 + +1.202.637.aahh 14:12:19 12http://www.w3.org/2010/policy-ws/papers/04-Hart-stonybrook.pdf 14:12:40 zakim, aahh is jmorris 14:12:40 +jmorris; got it 14:14:59 Topic: APIs 14:15:10 Topic: Contacts 14:15:13 zakim, who is here? 14:15:13 On the phone I see fjh, wonsuk, Dom, Claes, darobin, LauraA, richt, AnssiK, ilkka, nwidell, cmarc, +1.425.214.aagg, jmorris 14:15:16 On IRC I see jmorris, bryan, cmarc, nwidell, Dong-Young, LauraA, AnssiK, Claes, Zakim, RRSAgent, fjh, darobin, richt, wmaslowski, shepazu, trackbot, ingmar, ilkka, dom 14:15:33 Event based invocation: 14:15:46 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0001.html 14:15:55 http://dev.w3.org/2009/dap/contacts/Overview.html#api-invocation-via-dom-events 14:16:22 [+1 from me] 14:16:36 Richard: Added an informative section on invocation via dom events 14:16:46 Robin: Wants it normative 14:17:42 ......go ahead and add it 14:18:45 (e.g. "touchstart") 14:18:49 q+ 14:18:55 ack ilkka 14:19:00 ....worries if we start whitelisting events 14:19:40 (there is a new proposed wg to work on touch interfaces) 14:19:54 ack ilkka 14:20:03 q+ 14:20:09 Richard: Will work on this and make it normative 14:20:14 touch working group, http://www.w3.org/2010/07/touchinterface-charter.html 14:20:41 q+ to respond to Illka RE: device API 14:20:48 Ilkka: Good optimization. Also usable in capture API 14:21:19 (I would start putting it individually in specs, and factoring it out only when it's clear that it's productive) 14:21:21 ...could we make it reusable? 14:21:27 ack richt 14:21:27 richt, you wanted to respond to Illka RE: device API 14:21:37 [+1 to dom] 14:21:59 Richard: Agrees, it could be applicable in capture API as well 14:22:15 ...need device element? 14:23:20 ...a JS way to call JS API 14:23:30 (I'm doubtful about this; had all sort of protections (in terms of styling, clickjacking, etc) IIRC) 14:23:31 [I'm starting to think we're doing a little too much design on the fly orally] 14:23:37 ....could deprecate device element? 14:24:22 Do we understand the privacy and security implications for this approach, and that be added to the section in this document? 14:25:03 [fjh, no, we don't really yet, but it's worth investigating] 14:25:07 (the other thing that the element is a streaming API, very relevant for capture, but possibly dinstiguishable) 14:25:19 [agree that it is worth investigating] 14:25:38 More productive to continue this discussion by e-mail 14:27:12 clickjacking, and coercion need review 14:27:53 ack bryan 14:29:11 q+ 14:29:12 Bryan: Could we describe clickjacking in security and rivacy section? 14:29:22 s/rivacy/privacy 14:29:51 Richard: Nothing is shared until the user chooses 14:30:44 robin: denial of service not an issue since picker is modal unlike window.open 14:31:07 -Claes 14:31:17 Rich: The prompt is modal.. 14:31:30 sorry lost phone connection 14:31:56 Yes, I am calling 14:32:00 rich: we should note this in the spec, even though it might appear controversial 14:32:04 -LauraA 14:32:43 q+ 14:33:45 ack AnssiK 14:33:49 +LauraA 14:34:06 having trouble calling in 14:34:16 nwidell has joined #dap 14:34:24 ansii: clickjacking could be a serious attach, a big concern 14:34:56 -ilkka 14:35:02 no 14:35:08 +[T-Systems] 14:35:28 s/no// 14:36:06 ansii: attack could make it likely to take picture etc without intending to. should take this seriously 14:36:16 present+ Ingmar_Kliche 14:36:19 s/this/this risk 14:37:09 rich: tested in various browsers with variety of means to generate click events, and can do now already, but gets stopped at dialog 14:37:12 ScribeNick: fjh 14:37:42 ansii: where do we find examples of clickjacking attacks 14:37:56 we could ask public-web-security? 14:38:05 +Claes 14:38:15 q? 14:38:23 Back, had to use US number 14:38:28 ack fjh 14:38:32 Scribenick: Claes 14:38:53 (so, maybe the -replacement idea should be put into a document on its own while we work on it?) 14:39:35 Rich: Normative or not? 14:39:41 +1 14:39:42 +ilkka 14:40:20 having separate document would address Ilkka's concern about reuse 14:40:37 zakim, [T-Systems] is Ingmar_Kliche 14:40:37 +Ingmar_Kliche; got it 14:41:07 (or just an action on rich?) 14:41:30 Proposed RESOLUTION: the -replacement idea should be put into a document on its own while we work on it 14:42:09 ACTION: Richard to put his ideas on -alternative in a separate editors draft 14:42:09 Created ACTION-283 - Put his ideas on -alternative in a separate editors draft [on Richard Tibbett - due 2010-10-13]. 14:42:45 Topic: Capture API 14:42:53 Action on review to review Privacy 14:42:53 Sorry, couldn't find user - on 14:43:14 Will be done withi two weeks 14:43:14 ACTION-251 due +2 weeks 14:43:14 ACTION-251 Review privacy text related to ISSUE-78 for capture due date now +2 weeks 14:43:16 q? 14:43:31 Topic: Calendar 14:43:39 Surresh not present 14:43:49 Topic: Sys Info 14:43:52 ACTION-213? 14:43:52 ACTION-213 -- Dong-Young Lee to review sysinfo draft after edits made -- due 2010-07-21 -- OPEN 14:43:52 http://www.w3.org/2009/dap/track/actions/213 14:44:06 http://lists.w3.org/Archives/Public/public-device-apis/2010Oct/0002.html 14:44:19 Is anyone aware of navigator.connection.type in Android? 14:44:32 I've pointed to it a couple of months ago 14:44:35 I'd like to approach Sys Info API security in a similar way... 14:44:46 ...limit the info available but no security prompts. 14:44:56 rrsagent, generate minutes 14:44:56 I have made the request to generate http://www.w3.org/2010/10/06-dap-minutes.html fjh 14:45:25 Rich: avigator.connection.type in Android says type of connection 14:45:29 s/ScribeNick: fjh// 14:45:55 s/fjh: sorry, no// 14:46:09 s/DAP 3279.*// 14:46:37 s/Present Cecile_Marc// 14:46:47 Rich: will be sent a propsal based on above 14:46:47 s/\]// 14:46:49 [some info on clickjacking from The Open Web Application Security Project: http://www.owasp.org/index.php/Clickjacking] 14:47:02 ...without security promting etc 14:47:03 (I agree network.connection.type is indeed pretty harmless a priori; enabling it would require a lot of changes to the architecture of sysinfo a priori) 14:47:09 s/^12//g 14:47:48 s/will be sent/will aim to produce 14:48:03 rrsagent, generate minutes 14:48:03 I have made the request to generate http://www.w3.org/2010/10/06-dap-minutes.html fjh 14:48:05 Dong: Have reviewed Sys Info. Would like more examples 14:48:19 (looking at the network interface in sysinfo, everything seems actually pretty harmless, even taken in combination; maybe the security model for networkinfo should be no prompt?) 14:48:27 ACTION-243? 14:48:27 ACTION-243 -- Dong-Young Lee to review sysinfo draft after edits made -- due 2010-08-09 -- OPEN 14:48:27 http://www.w3.org/2009/dap/track/actions/243 14:48:32 ACTION-243 closed 14:48:32 ACTION-243 Review sysinfo draft after edits made closed 14:48:35 s/Rich: avigator.connection.type/Rich: navigator.connection.type 14:48:46 ACTION-243: feedback is: more examples would make the document easier to understand 14:48:46 ACTION-243 Review sysinfo draft after edits made notes added 14:49:01 rrsagent, generate minutes 14:49:01 I have made the request to generate http://www.w3.org/2010/10/06-dap-minutes.html fjh 14:49:06 Note call canceled next week 14:49:07 -darobin 14:49:09 - +1.425.214.aagg 14:49:11 -jmorris 14:49:13 -nwidell 14:49:15 -Dom 14:49:17 -richt 14:49:18 -AnssiK 14:49:19 -fjh 14:49:24 -cmarc 14:49:26 -Ingmar_Kliche 14:49:28 -Claes 14:49:29 -LauraA 14:49:36 -wonsuk 14:50:05 fjh_ has joined #dap 14:53:17 zakim, who is here? 14:53:17 On the phone I see ilkka 14:53:18 On IRC I see fjh_, bryan, AnssiK, Zakim, RRSAgent, fjh, darobin, richt, wmaslowski, shepazu, trackbot, ingmar, ilkka, dom 15:05:31 richt_ has joined #dap 15:25:36 tlr has joined #dap 15:35:01 disconnecting the lone participant, ilkka, in UW_DAP()10:00AM 15:35:03 UW_DAP()10:00AM has ended 15:35:07 Attendees were fjh, Dom, +46.1.08.01.aaaa, Claes, +44.777.541.aabb, darobin, +44.757.091.aacc, LauraA, wonsuk, richt, +358.504.86aadd, AnssiK, +358.504.86aaee, ilkka, 15:35:09 ... +46.1.07.15.aaff, nwidell, +1.425.214.aagg, cmarc, +1.202.637.aahh, jmorris, Ingmar_Kliche 15:35:30 fjh_ has left #dap 15:46:25 fjh has left #dap 16:01:23 tlr has joined #dap 17:02:39 Zakim has left #dap