14:23:58 RRSAgent has joined #webappsec 14:23:58 logging to http://www.w3.org/2014/09/10-webappsec-irc 14:59:19 gmaone has joined #webappsec 15:02:20 Zakim. :( 15:03:20 bhill2 has joined #webappsec 15:04:06 bhill2 has changed the topic to: http://lists.w3.org/Archives/Public/public-webappsec/2014Sep/0047.html 15:04:15 zakim, who is here? 15:04:15 sorry, bhill2, I don't know what conference this is 15:04:17 On IRC I see bhill2, gmaone, RRSAgent, Zakim, dveditz, terri, freddyb, mkwst, timeless, tobie, wseltzer, trackbot 15:04:20 zakim, this is 92794 15:04:20 ok, bhill2; that matches SEC_WASWG()11:00AM 15:04:24 zakim, who is here? 15:04:24 On the phone I see dveditz, BHill, mkwst 15:04:26 On IRC I see bhill2, gmaone, RRSAgent, Zakim, dveditz, terri, freddyb, mkwst, timeless, tobie, wseltzer, trackbot 15:04:40 Meeting: WebAppSec WG Teleconference 10-September-2014 15:04:42 Agenda: http://lists.w3.org/Archives/Public/public-webappsec/2014Sep/0047.html 15:04:58 Chairs: dveditz, bhill 15:04:59 +??P13 15:05:25 zakim, ??P13 is me 15:05:25 +gmaone; got it 15:06:15 + +1.360.562.aaaa 15:06:58 zakim, aaaa is kevinhill 15:06:58 +kevinhill; got it 15:08:07 ShijunS has joined #webappsec 15:08:31 zakim, who is here? 15:08:31 On the phone I see dveditz, BHill, mkwst, gmaone, kevinhill 15:08:33 On IRC I see ShijunS, bhill2, gmaone, RRSAgent, Zakim, dveditz, terri, freddyb, mkwst, timeless, tobie, wseltzer, trackbot 15:09:04 topic: minutes approval 15:09:06 http://www.w3.org/2011/webappsec/draft-minutes/2014-08-27-webappsec-minutes.html 15:09:51 dveditz: Any objections to publishing minutes? 15:09:52 scribenick: mkwst 15:09:54 15:10:05 dveditz: No objections, approved. 15:10:24 TOPIC: Review of Open Actions in the Tracker 15:11:14 TOPIC: agenda bashing 15:11:17 bhill2: Perhaps we can skip around a bit, due to low attendence. 15:11:27 bhill2: Are there particular topics of interest? 15:11:38 kevinhill: child-src looks interesting. 15:11:48 dveditz: I drop my objection. 15:12:15 kevinhill: Working on 1.0 implementation. 15:12:30 kevinhill: Level 2 looks interesting. We think it's a good spec. 15:12:37 kevinhill: Adoption is a topic I'd like to cover. 15:12:55 kevinhill: CSP is struggling with adoption. Working in MS to get services to adopt CSP. 15:13:12 kevinhill: Worthwhile to band together to help websites adopt? 15:13:28 kevinhill: Yelp, for instance, is doing interesting work. 15:14:14 mkwst: I agree that it's important to get adoption. 15:14:36 mkwst: internal google properties are adopting: Gmail, Plus, YouTube, etc. 15:14:43 kevinhill: thinking of sites outside MS and Google. 15:14:52 kevinhill: nice to see Yelp, for instance. 15:15:19 kevinhill: important to highlight folks in the community, help the wider net understand the value. 15:15:31 dveditz: people come up with super-complex policies that break all the time. 15:15:50 dveditz: suggesting that folks come up with simpler policies, focusing on script-src. 15:16:05 dveditz: not a first-line of defense. 15:16:26 dveditz: other complaint is reporting: discover how terrible the web is, lots of unexpected errors. 15:16:33 dveditz: add-ons, ISPs, etc. 15:16:45 dveditz: separating real attacks from noise is difficult. 15:17:48 kevinhill: This is more or less what the Yelp article addresses. 15:18:10 bhill2: setting up some sort of CSP-support mailing list would be helpful. 15:18:45 bhill2: shared report-processing mechanisms, code would be excellent 15:19:00 kevinhill: want to go to tooling folks at MS to see what could be done. 15:19:13 kevinhill: perhaps VS could help developers construct policies. 15:19:20 kevinhill: tooling around IIS for analysis. 15:19:34 kevinhill: the more public we can be in the community, the more helpful for folks. 15:19:48 kevinhill: publish stats about what's being prevented, etc. 15:20:37 kevinhill: smartscreen filter in the browser. publish statistics. 15:21:25 dveditz: telemetry reporting to the browser? could report what is being blocked for users. 15:21:34 dveditz: might be interesting. will talk to folks about that. 15:22:20 kevinhill: comcast example. 15:22:53 mkwst: https is necessary. 15:23:05 bhill2: CSP is a discovery mechanism to understand why HTTPS is critical. 15:24:08 dveditz: browser helper objects that inject content? 15:24:14 kevinhill: Haven't thought about it much. 15:24:21 gmaone2 has joined #webappsec 15:24:38 dveditz: it's a problem everyone has. chrome tries to allow extensions to work. 15:24:57 +??P0 15:24:59 kevinhill: progress is being made there. i agree that it's important. 15:25:37 zakim, ??P0 is me 15:25:37 +gmaone2; got it 15:26:18 thx 15:26:50 mkwst: 1. CSP2 to CR? 2. What does "widely review" mean in the context of the WG? 15:27:09 bhill: 1. Take the doc we're working on and bring it to Director for publication. 15:27:52 bhill: Notify other groups, invite them to take a look at CSP2. Point to blog posts, and presentations, etc. 15:29:02 15:30:39 +[Microsoft] 15:30:49 15:31:06 15:31:34 zakim, Microsoft has David Walp 15:31:34 +David, Walp; got it 15:31:38 mkwst: MIX? Do we wait until the next call? I'd like to get a draft out. 15:31:41 zakim, who is here? 15:31:41 On the phone I see dveditz, BHill, mkwst, gmaone, kevinhill, gmaone2, [Microsoft] 15:31:44 [Microsoft] has David, Walp 15:31:44 On IRC I see gmaone2, ShijunS, bhill2, RRSAgent, Zakim, dveditz, terri, freddyb, mkwst, timeless, tobie, wseltzer, trackbot 15:32:07 bhill2: Any objections to publishing a new WD of MIX? 15:32:21 : No objections. 15:32:51 bhill2: Ok, we'll take it to the list. 15:33:06 mkwst: Perhaps we could move the call down again? I can do a slightly later call. 15:33:16 ACTION bhill2 to reconsider call time 15:33:16 Created ACTION-187 - Reconsider call time [on Brad Hill - due 2014-09-17]. 15:33:50 -BHill 15:33:50 bhill2: Dropping to hit the WebCrypto workshop. 15:34:01 TOPIC: [CSP] kill or delay child-src? 15:34:16 dveditz: My confusion. Widthdraw question. 15:34:47 davidwalk: Last item: XHR. 15:35:06 TOPIC: XMLHttpRequest. Support for OPTIONS* method. 15:36:13 mkwst: That's a thread that's probably best dealt with on the list, as the folks on that thread don't generally call into WebAppSec. 15:36:40 dveditz: Started in public-webapps@. Probably best to do it via mail. 15:37:37 dveditz: Ok. Let's call it early today. 15:38:23 -kevinhill 15:38:25 -[Microsoft] 15:38:25 -dveditz 15:38:29 -mkwst 15:38:30 -gmaone2 15:39:00 rrsagent, make minutes 15:39:00 I have made the request to generate http://www.w3.org/2014/09/10-webappsec-minutes.html bhill2 15:39:04 rrsagent, set logs public-visible 16:05:00 disconnecting the lone participant, gmaone, in SEC_WASWG()11:00AM 16:05:02 SEC_WASWG()11:00AM has ended 16:05:02 Attendees were dveditz, BHill, mkwst, gmaone, +1.360.562.aaaa, kevinhill, gmaone2, David, Walp 16:28:44 bhill2 has left #webappsec 17:52:03 Zakim has left #webappsec