14:59:30 RRSAgent has joined #websec 14:59:30 logging to http://www.w3.org/2014/05/06-websec-irc 14:59:36 Meeting: Web Security IG 14:59:41 Chair: Virginie Galindo 14:59:50 Date: 6 May 2014 15:00:23 kodonog has joined #websec 15:00:27 Agenda: http://lists.w3.org/Archives/Public/public-web-security/2014May/0000.html 15:00:39 wseltzer has changed the topic to: Web Security IG, 6 May: http://lists.w3.org/Archives/Public/public-web-security/2014May/0000.html 15:01:22 zakim, code? 15:01:23 the conference code is 26634 (tel:+1.617.761.6200 sip:zakim@voip.w3.org), wseltzer 15:01:26 zakim, who is on the call ? 15:01:27 SEC_WSIG()11:00AM has not yet started, virginie 15:01:28 On IRC I see kodonog, RRSAgent, christine, Zakim, trackbot, virginie, terri_, fjh, Sanjeev, terri, wseltzer 15:01:50 zakim, this is WSIG 15:01:51 ok, wseltzer; that matches SEC_WSIG()11:00AM 15:01:54 antonio has joined #websec 15:01:58 zakim, who is on the call? 15:01:58 On the phone I see +1.408.412.aabb, [IPcaller], [IPcaller.a], +33.4.42.36.aacc, BHill, karen_oDonoghue, WSeltzer, +1.613.287.aadd 15:02:09 +terri 15:02:12 zakim, aacc is virginie 15:02:12 +virginie; got it 15:02:33 Zakim, 15:02:33 I don't understand '', christine 15:02:49 Zakim, [IPcaller] is me 15:02:49 +christine; got it 15:03:02 41 is switzerland 15:03:09 zakim, aadd is Irdeto 15:03:09 +Irdeto; got it 15:03:17 zakim, aacc is me 15:03:17 sorry, virginie, I do not recognize a party named 'aacc' 15:03:23 zakim, Irdeto has Harold_Johnson 15:03:23 +Harold_Johnson; got it 15:03:29 bhill2 has joined #websec 15:03:33 zakim, who is on the call ? 15:03:33 On the phone I see +1.408.412.aabb, christine, [IPcaller.a], virginie, BHill, karen_oDonoghue, WSeltzer, Irdeto, terri 15:03:35 Irdeto has Harold_Johnson 15:03:57 +[IPcaller] 15:04:01 zakim, ipcaller is me 15:04:01 +fjh; got it 15:04:07 Present+ Frederick_Hirsch 15:04:13 zakim, aabb is Sanjiv 15:04:13 +Sanjiv; got it 15:04:28 zakim, who is here? 15:04:30 On the phone I see Sanjiv, christine, [IPcaller.a], virginie, BHill, karen_oDonoghue, WSeltzer, Irdeto, terri, fjh 15:04:30 Irdeto has Harold_Johnson 15:04:30 On IRC I see bhill2, antonio, kodonog, RRSAgent, christine, Zakim, trackbot, virginie, terri_, fjh, Sanjeev, terri, wseltzer 15:04:58 zakim, Ipcaller.a is antonio 15:04:58 +antonio; got it 15:05:19 agenda+ Welcome 15:05:25 http://lists.w3.org/Archives/Public/public-web-security/2014May/0000.html 15:05:28 agenda+ OWASP presentation (by Antonio FONTES from OWASP) 15:05:36 agenda+ SysApp WG security model (by Dave RAGGETT from W3C) 15:05:43 agenda+ Report from W3C Web Payment Workshop, with a special focus on identity, security and privacy, and a little bit of STRINT 15:05:50 agenda+ Status on next W3C Workshop related to secure token and secure services, 15:05:59 agenda+ Action items for the IG 15:06:02 agenda+ AOB 15:06:05 agenda? 15:06:13 zakim, take up agendum 1 15:06:13 agendum 1. "Welcome" taken up [from wseltzer] 15:06:28 Virginie: Welcome, review agenda 15:06:55 zakim, who is on the call ? 15:06:55 On the phone I see Sanjiv, christine, antonio, virginie, BHill, karen_oDonoghue, WSeltzer, Irdeto, terri, fjh 15:06:58 Irdeto has Harold_Johnson 15:08:07 HJJJr has joined #websec 15:08:24 zakim, next agendum 15:08:24 agendum 2. "OWASP presentation (by Antonio FONTES from OWASP)" taken up [from wseltzer] 15:09:09 Virginie: Wanted to increase interaction between OWASP and W3C on Web security 15:09:28 Antonio: I work in info sec, specializing in web app security 15:09:40 ... involved in OWASP since 2008 15:09:44 OWASP foundation website : https://www.owasp.org/index.php/Main_Page 15:09:50 ... not official representative 15:10:10 ... Open Web Application Security Project 15:10:29 ... organized around foundation, mission to help management make informed decisions on web application security 15:10:43 ... guidance, tools, info, frameworks, best practices, references 15:10:53 ... to manage lifecycle of applications 15:12:34 ... Documents, conferences, 15:12:48 OWASP conferences https://www.owasp.org/index.php/Category:OWASP_AppSec_Conference 15:13:08 ... Chapters, more than 200 worldwide 15:13:21 OWASP chapters https://www.owasp.org/index.php/OWASP_Chapter 15:14:29 ... Chapters build connection to local level 15:14:32 q? 15:14:59 Virginie: How can we interact, work with you on deliverables? 15:15:11 Antonio: Should talk about mailing lists 15:15:19 ... have more than 36k members registered on lists 15:15:30 ... to share info, get feedback 15:15:48 OWASP mailing lists: https://lists.owasp.org/mailman/listinfo 15:16:25 Antonio: mailing lists could be avenue for collaboration 15:16:38 ... Documentation project sometimes reviews externally produced docs 15:16:47 ... to provide guidance, suggestions 15:17:51 ... Top 10 Web App Sec Security Risks 15:18:06 ... Every year, collect factual data to identify risks 15:18:27 ... used by orgs for reference, fast overview 15:18:38 https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project 15:18:54 ... Review against this top 10, at least 15:18:57 ... ASVS 15:19:13 ... Aims at standardizing entire verification set 15:19:16 https://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project 15:19:36 ... everything you should verify in a web app that asserts it's secure 15:20:03 ... ZAP Proxy, a tool that helps testing of web apps 15:20:10 https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project 15:20:15 ... downloadable from OWASP 15:20:30 ... @@API, library of secure code 15:20:39 ... questions? 15:20:43 q? 15:21:01 the library is the ESAPI 15:21:07 Entreprise Security API 15:21:13 q+ 15:22:35 ESAPI (The OWASP Enterprise Security API) https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API 15:23:12 wseltzer: @@ 15:23:14 dsr has joined #websec 15:23:22 q? 15:23:46 Virginie: Great to hear of the number of people involved in OWASP activities 15:24:00 fjh: Do you have info on usage of verifications 15:24:31 ... @@ 15:24:55 antonio: we are trying get better usage information 15:25:03 ... we know governments are using ASVS 15:25:13 ... as standard for internal development 15:25:47 ... We have seen Top 10 integrated in almost all security reference 15:26:25 +Dsr 15:26:33 second question was whether you are seeing anything related to Target breach, which has had big business impact, any new work based on this 15:26:46 ... We have no large standards-level reference to ASVS 15:28:07 thanks, that all makes sense regarding asvs 15:28:22 ... hard to get reference to 140 controls 15:29:10 HJJJr has joined #websec 15:29:18 fjh: Did Target breach have repercussions? 15:30:24 Antonio: Yes. Any breach that gets lots of media attention calls attention to security 15:30:51 ... but we don't often get details about the vulnerability, whereas we did in Target. 15:31:44 yes, target will be a great use case for justification for need of security analysis etc 15:31:59 virgine: We'll see how to collaborate in follow-up 15:32:09 thanks Antonio for excellent summary 15:32:41 zakim, next agendum 15:32:41 I see a speaker queue remaining and respectfully decline to close this agendum, wseltzer 15:32:47 ack fjh 15:32:49 zakim, next agendum 15:32:49 agendum 3. "SysApp WG security model (by Dave RAGGETT from W3C)" taken up [from wseltzer] 15:32:52 http://www.w3.org/2012/sysapps/ 15:33:10 Virgine: Thanks Dave Raggett for joining to discuss SysApps 15:33:29 dsr: SysApps is looking at giving web developers rich access to device capabilities 15:33:40 ... requiring greater levels of trust than normal APIs 15:33:47 http://www.w3.org/2012/09/sysapps-wg-charter.html 15:34:23 ... started with 2 phases of work, may re-charter 15:34:37 ... Rich capabilities, example Sony's work on access to raw sockets 15:34:48 ... That's not something you'd want to give to arbitrary web app 15:35:00 ... 2 classes of apps. Packaged install, hosted app on website 15:35:10 ... For both, thinking about manifest 15:35:23 ... earlier w3c work on widgets not widely deployed 15:35:34 ... JSON manifest started in SysApps, transferring to WebApps 15:35:44 ... info about the app, e.g. full-scree 15:35:49 s/scree/screen/ 15:36:09 ... App URI, allowing apps, whether hosted or packaged, to download resources in the same way 15:36:17 ... Security and permissions 15:36:50 ... open meeting re trust and permissions 15:36:58 ... also rechartering 15:37:06 doodle for participating http://doodle.com/6mequ2befp3ax592#table 15:37:18 ... different approaches: Native apps, Android list permissions up-front 15:37:26 ... iOS run-time request to user 15:37:32 ... relates to EULAs 15:38:01 ... How shoudl we do this on the Web? 15:38:11 ... experence from Device APIs, Geoloc 15:38:29 ... privacy 15:39:01 ... privacy footprint 15:39:10 ... do users understand questions they're being asked? 15:39:12 s/shoudl/should/ 15:39:53 q+ 15:40:24 -virginie 15:40:27 terri: question on manifests and security 15:40:38 dsr: work on manifests in webapps 15:40:50 ... some companies would like to add permissions in manifest 15:41:01 +virginie 15:41:09 ... if we want to allow devs to deal with manifests, need standard naming 15:42:12 q? 15:42:26 q 15:42:33 ack fjh 15:42:34 q+ 15:42:54 fjh: Is it correct to say security model needs work, using th workshop to progress? 15:43:08 dsr: Yes, runtime security model discontinued 15:43:52 q? 15:44:35 ack christine 15:45:20 christine: Please come talk to PING regarding privacy considerations 15:45:21 q+ 15:45:24 dsr: thanks, will do 15:45:28 ack terri 15:45:42 terri: How does sysapps interact with CSP? 15:45:57 dsr: more webapps than sysapps 15:46:12 ... some discussion, still ongoing 15:46:27 ... woudl be able to use CSP, based on same-origin model 15:46:40 ... other things to do with trust 15:46:51 ... how does that affect permisioning model 15:47:08 ... browsers vary on how they remember "clicked yes" 15:47:17 ... based on HTTPs 15:47:39 virginie: thanks, we'll loook forward to hearing about the workshop 15:48:29 zakim, next agendum 15:48:29 agendum 4. "Report from W3C Web Payment Workshop, with a special focus on identity, security and privacy, and a little bit of STRINT" taken up [from wseltzer] 15:48:45 Virgine: reports from workshops 15:48:52 Payment report http://www.w3.org/2013/10/payments/final_report.html 15:49:53 virginie: discussion of privacy and security; several references to trusted user interface 15:50:33 ... re payments, w3c is looking to charter new Interest Group 15:50:45 STRINT report https://tools.ietf.org/html/draft-iab-strint-report-00 15:51:01 What may fall in W3C http://lists.w3.org/Archives/Public/public-web-security/2014Apr/0008.html 15:55:59 zakim, next agendum 15:55:59 agendum 5. "Status on next W3C Workshop related to secure token and secure services," taken up [from wseltzer] 15:56:34 Virginie: Worshop on secure tokens and hardware authentication 15:56:40 ... Sept 10-11 in Mountain View 15:56:52 ... has been approved by w3c, will share info soon 15:57:10 ... working with FIDO Alliance, smartcard vendors 15:57:30 ... how to integrate hw security for secure authentication 15:57:35 zakim, next agendum 15:57:35 agendum 6. "Action items for the IG" taken up [from wseltzer] 15:57:56 We have a recent proposal from Wendy to take web rtc as a possible http://lists.w3.org/Archives/Public/public-web-security/2014Apr/0006.html 15:58:30 Virginie: actions; e.g. Wendy's thinking on webrtc and Web Security model 15:58:41 ... end these calls with call for volunteers, info share 15:59:12 -Dsr 15:59:17 https://www.w3.org/Security/wiki/IG 15:59:27 ... e.g. volunteers for web security guidelines 15:59:31 https://www.w3.org/Security/wiki/IG/W3C_spec_review 15:59:50 https://www.w3.org/Security/wiki/IG/W3C_spec_review/Security_Guidelines 16:00:35 q? 16:01:07 virginie: thanks, and keep in touch on the list 16:01:15 -BHill 16:01:15 -christine 16:01:15 -karen_oDonoghue 16:01:16 -fjh 16:01:16 -Irdeto 16:01:17 [adjourned] 16:01:24 -virginie 16:01:28 -terri 16:01:30 -antonio 16:01:37 -WSeltzer 16:01:39 rrsagent, make minutes 16:01:39 I have made the request to generate http://www.w3.org/2014/05/06-websec-minutes.html wseltzer 16:01:50 thank you all 16:02:22 thanks antonio, dave and all participants 16:05:24 antonio has left #websec 16:06:37 disconnecting the lone participant, Sanjiv, in SEC_WSIG()11:00AM 16:06:39 SEC_WSIG()11:00AM has ended 16:06:39 Attendees were +1.613.287.aaaa, +1.408.412.aabb, +33.4.42.36.aacc, BHill, karen_oDonoghue, WSeltzer, +1.613.287.aadd, terri, virginie, christine, Harold_Johnson, fjh, Sanjiv, 16:06:39 ... antonio, Dsr 16:58:50 rrsagent, make logs public 16:58:55 rrsagent, make minutes 16:58:55 I have made the request to generate http://www.w3.org/2014/05/06-websec-minutes.html wseltzer 17:00:12 s/wseltzer: @@/wseltzer: We look forward to discussing closer work with OWASP, including possible collaboration on reviews 17:00:21 s/@@API/ESAPI/ 17:00:54 rrsagent, make minutes 17:00:54 I have made the request to generate http://www.w3.org/2014/05/06-websec-minutes.html wseltzer 18:07:00 terri_ has joined #websec