21:59:02 RRSAgent has joined #webappsec 21:59:02 logging to http://www.w3.org/2013/12/17-webappsec-irc 21:59:10 zakim, this will be 92794 21:59:10 ok, bhill2; I see SEC_WASWG()5:00PM scheduled to start in 1 minute 21:59:50 gopal has joined #webappsec 22:00:25 Meeting: WebAppSec Teleconference, 17 DEC 2013 22:00:30 Chair: bhill2 22:00:36 Agenda: http://lists.w3.org/Archives/Public/public-webappsec/2013Dec/0074.html 22:00:47 grobinson|laptop has joined #webappsec 22:00:55 Scribe: Peleus Uhley 22:00:59 Scribenick: puhley 22:01:13 zakim, who is here? 22:01:13 SEC_WASWG()5:00PM has not yet started, bhill2 22:01:14 On IRC I see grobinson, gopal, RRSAgent, Zakim, puhley, bhill2, neilm, terri, gmaone, timeless, wseltzer, trackbot 22:01:36 rrsagent, make minutes 22:01:36 I have made the request to generate http://www.w3.org/2013/12/17-webappsec-minutes.html bhill2 22:01:40 rrsagent, set logs public-visible 22:01:51 zakim, who is here? 22:01:51 SEC_WASWG()5:00PM has not yet started, bhill2 22:01:52 On IRC I see grobinson, gopal, RRSAgent, Zakim, puhley, bhill2, neilm, terri, gmaone, timeless, wseltzer, trackbot 22:02:14 jww has joined #webappsec 22:02:46 zakim, who is here? 22:02:46 SEC_WASWG()5:00PM has not yet started, bhill2 22:02:47 On IRC I see jww, grobinson, gopal, RRSAgent, Zakim, puhley, bhill2, neilm, terri, gmaone, timeless, wseltzer, trackbot 22:02:53 zakim, this is 92794 22:02:53 ok, bhill2; that matches SEC_WASWG()5:00PM 22:02:57 -??P6 22:03:00 zakim, what time is it? 22:03:01 I don't understand your question, bhill2. 22:03:11 zakim, who is here? 22:03:11 On the phone I see +1.415.832.aaaa, BHill, +1.503.712.aabb, +1.781.369.aacc, +1.415.736.aadd, Wendy, [Mozilla], ??P9 22:03:14 On IRC I see jww, grobinson, gopal, RRSAgent, Zakim, puhley, bhill2, neilm, terri, gmaone, timeless, wseltzer, trackbot 22:03:14 +??P6 22:03:25 +NeilM 22:03:28 zakim, aaaa is puhley 22:03:28 +puhley; got it 22:03:28 Zakim, ??P6 is gmaone 22:03:29 +gmaone; got it 22:03:37 zakim, aabb is terri 22:03:37 +terri; got it 22:03:41 [Mozilla] is grobinson 22:03:52 zakim, who is here? 22:03:52 On the phone I see puhley, BHill, terri, +1.781.369.aacc, +1.415.736.aadd, Wendy, [Mozilla], ??P9, gmaone, NeilM 22:03:52 (i'll add myself) 22:03:54 On IRC I see jww, grobinson, gopal, RRSAgent, Zakim, puhley, bhill2, neilm, terri, gmaone, timeless, wseltzer, trackbot 22:04:18 Zakim: [Mozilla] is grobinson 22:04:22 zakim, aacc is gopal 22:04:22 +gopal; got it 22:04:35 wseltzer_ has joined #webappsec 22:04:39 zakim, aadd is jww 22:04:39 +jww; got it 22:05:11 http://lists.w3.org/Archives/Public/public-webappsec/2013Dec/0074.html 22:05:45 TOPIC: Minutes approval 22:05:46 http://www.w3.org/2013/12/03-webappsec-minutes.html 22:05:57 + +1.404.406.aaee 22:06:07 minutes approved, no objection to unanimous approval 22:06:31 freddyb has joined #webappsec 22:06:45 zakim, aaee is danesh 22:06:45 +danesh; got it 22:06:56 TOPIC: Agenda bashing 22:07:15 TOPIC: News 22:07:56 bhill2: CORS is moving to proposed recommendation. Encourage reps to comment on the spec and indicate support. 22:08:35 bhill2: Hope for final recommendation status in January and February 22:08:40 TOPIC: Open actions in Tracker 22:08:47 https://www.w3.org/2011/webappsec/track/actions/open?sort=owner 22:09:42 bhill2: Action 158 is complete 22:10:34 TOPIC: Sub-Resource Integrity 22:12:02 <- 22:12:17 hey freddyb :) 22:12:19 bhill2: sub-resource integrity is part of our new charter. Editors recruited: Devdatta, Joel(jww), and Fredrick (freddyb) 22:12:41 puhley: Frederi_k_ please :-) 22:12:43 hi grobinson 22:12:57 My apologies... 22:13:27 np 22:14:21 TOPIC: Hash/nonce source 22:14:29 http://lists.w3.org/Archives/Public/public-webappsec/2013Dec/0072.html 22:15:00 bhill2: Good thread on the mailing lists regarding this topic 22:17:14 Neil: Confusion over hashes only applying to inline scripts/event handlers, nonces applying to both inline scripts and external resources 22:19:45 bhill2: Does whitelisting event handlers make sense? What about styles? 22:21:42 bhill2: (Summarizing discussion) Supporting edge cases adds complexity that may not be worth effort when there is alternative methods for addressing the issue. 22:22:45 bhill2: Neil will take action to reply to the list with summary of the discussion on the phone. 22:23:03 ACTION neilm to respond to list re: consensus that applying hash/nonce to inline handlers not desired as a 1.1 feature 22:23:03 Created ACTION-159 - Respond to list re: consensus that applying hash/nonce to inline handlers not desired as a 1.1 feature [on Neil Matatall - due 2013-12-24]. 22:23:19 TOPIC: Cascading style-src onto font-src 22:23:23 http://lists.w3.org/Archives/Public/public-webappsec/2013Dec/0011.html 22:24:40 bhill2: Should we apply style-src as an intermediary between font-src and default-src? 22:25:21 ACTION bhill2 to reply to jonas sicking on list re: cascade of style-src to font-src 22:25:21 Created ACTION-160 - Reply to jonas sicking on list re: cascade of style-src to font-src [on Brad Hill - due 2013-12-24]. 22:25:36 TOPIC: UISecurity and frame-ancestors 22:25:39 bhill2: Will remain at no action state since no one on the phone had a strong opinion on it 22:25:42 http://lists.w3.org/Archives/Public/public-webappsec/2013Dec/0073.html 22:26:43 bhill2: Propose moving directives over into mainline of CSP 1.1 22:26:51 no objections to unanimous consent 22:27:20 ACTION bhill2 to abandon CfC on UISecurity to LCWD for now 22:27:21 Created ACTION-161 - Abandon cfc on uisecurity to lcwd for now [on Brad Hill - due 2013-12-24]. 22:27:45 bhill2: Next call will be skipped due to New Years Eve 22:28:02 -NeilM 22:28:05 -jww 22:28:06 -[Mozilla] 22:28:06 -gopal 22:28:07 -danesh 22:28:09 zakim, list attendees 22:28:09 As of this point the attendees have been +1.415.832.aaaa, BHill, +1.503.712.aabb, NeilM, +1.781.369.aacc, +1.415.736.aadd, Wendy, [Mozilla], puhley, gmaone, terri, gopal, jww, 22:28:12 ... +1.404.406.aaee, danesh 22:28:12 -??P9 22:28:13 -gmaone 22:28:14 gopal has left #webappsec 22:28:15 -terri 22:28:30 -Wendy 22:28:39 the ??P9 might have been me 22:28:45 -puhley 22:28:51 zakim, ??P9 is freddyb 22:28:51 I already had ??P9 as ??P9, bhill2 22:29:05 rrsagent, make minutes 22:29:05 I have made the request to generate http://www.w3.org/2013/12/17-webappsec-minutes.html bhill2 22:29:11 rrasagent, set logs public-visible 22:29:41 -BHill 22:29:43 SEC_WASWG()5:00PM has ended 22:29:43 Attendees were +1.415.832.aaaa, BHill, +1.503.712.aabb, NeilM, +1.781.369.aacc, +1.415.736.aadd, Wendy, [Mozilla], puhley, gmaone, terri, gopal, jww, +1.404.406.aaee, danesh 22:29:59 freddyb has left #webappsec 22:31:28 grobinson has joined #webappsec 22:32:50 terri_ has joined #webappsec 23:35:27 grobinson has joined #webappsec