21:55:00 RRSAgent has joined #webappsec 21:55:00 logging to http://www.w3.org/2012/01/03-webappsec-irc 21:55:17 zakim, this is 92794 21:55:17 bhill2, I see SEC_WASWG()5:00PM in the schedule but not yet started. Perhaps you mean "this will be 92794". 21:55:26 zakim, this will be 92794 21:55:26 ok, bhill2; I see SEC_WASWG()5:00PM scheduled to start in 5 minutes 21:55:45 Meeting: WebAppSec WG Call, 3 Jan 2012 21:55:54 SEC_WASWG()5:00PM has now started 21:56:01 +??P0 21:56:04 Chair: bhill2, ekr 21:56:20 Agenda: http://lists.w3.org/Archives/Public/public-webappsec/2012Jan/0000.html 21:57:12 + +1.650.678.aaaa 21:57:17 abarth has joined #webappsec 21:57:26 zakim, who is here? 21:57:26 On the phone I see ??P0, +1.650.678.aaaa 21:57:27 On IRC I see abarth, RRSAgent, Zakim, gma1, bubble, bhill21, bhill2, ekr, anne, trackbot 21:57:38 zakim, aaaa is ekr 21:57:38 +ekr; got it 21:57:44 zakim, who is here 21:57:44 ekr, you need to end that query with '?' 21:57:44 zakim, ??P0 is gma1 21:57:46 +gma1; got it 21:57:48 + +1.650.648.aabb 21:57:49 zakim, who is here? 21:57:51 On the phone I see gma1, ekr, +1.650.648.aabb 21:57:53 On IRC I see abarth, RRSAgent, Zakim, gma1, bubble, bhill21, bhill2, ekr, anne, trackbot 21:58:01 + +1.303.229.aacc 21:58:11 zakim, aacc is bhill2 21:58:11 +bhill2; got it 21:58:13 Zakim: aabb is abarth 21:58:21 Zakim, aabb is abarth 21:58:21 +abarth; got it 21:58:44 Zakim: y u no remember my phone number? 21:59:23 + +1.503.712.aadd 21:59:30 + +1.408.234.aaee 22:00:08 rrware has joined #webappsec 22:00:45 krisk has joined #webappsec 22:01:13 zakim doesn't remember me either 22:01:52 zakim, who is here 22:01:52 bhill2, you need to end that query with '?' 22:01:56 zakim, who is here? 22:01:56 On the phone I see gma1, ekr, abarth, bhill2, +1.503.712.aadd, +1.408.234.aaee 22:01:58 On IRC I see krisk, rrware, abarth, RRSAgent, Zakim, gma1, bubble, bhill21, bhill2, ekr, anne, trackbot 22:02:10 +[Microsoft] 22:02:18 + +1.415.832.aaff 22:02:36 zakim, Microsoft is me 22:02:36 +krisk; got it 22:03:21 + +1.650.224.aagg 22:04:49 +[Microsoft] 22:05:23 zakim, +1.503.712.aadd is me 22:05:23 +rrware; got it 22:05:24 jrossi has joined #webappsec 22:05:57 http://lists.w3.org/Archives/Public/public-webappsec/2012Jan/0000.html 22:06:03 that's today's agenda, for those joining late 22:06:06 q+ 22:06:19 ack krisk 22:06:59 zakim, who is here? 22:06:59 On the phone I see gma1, ekr, abarth, bhill2, rrware, +1.408.234.aaee, krisk, +1.415.832.aaff, +1.650.224.aagg, [Microsoft] 22:07:01 On IRC I see jrossi, krisk, rrware, abarth, RRSAgent, Zakim, gma1, bubble, bhill21, bhill2, ekr, anne, trackbot 22:07:25 I just wanted to confirm that we all agree to have the webappsec WG to hold the CORS tests cases and not have them in webapps 22:07:58 bhill, minutes approved from last meeting 22:07:59 http://www.w3.org/2011/webappsec/track/actions/open 22:08:37 bhill to update due date of activity 1 22:09:22 Action 34 pushed out 2 weeks. 22:09:22 Sorry, couldn't find user - 34 22:09:30 you can't hear m? 22:09:34 No. 22:10:29 Action 35 pushed out to next call. 22:10:29 Sorry, couldn't find user - 35 22:10:29 zakim, who is speaking 22:10:29 I don't understand 'who is speaking', bhill2 22:12:24 Gopal has volunteered to be the test coordinator for webappsec testing. 22:12:40 - +1.408.234.aaee 22:13:38 Plan at the moment is to use the same process that webapp uses. In the process of building a virtual machine for use in testing 22:14:18 Moving the CORS test MS created into the webappsec test folder. 22:14:32 Couple of tests need approval for changes in the php config. 22:14:42 Need input from Dominique. 22:14:44 For those unfamiliar, here's the WebApps testing process (infrastructure, submission, approval, harness, etc.): http://www.w3.org/2008/webapps/wiki/Testing 22:15:48 CORS CfC comments 22:17:05 bhill: Concern that the issues and objections raised by UMP have not been fully addressed by CORS. Spec is incomplete around security considerations. After back-and-forth on TAG list, 22:17:34 http://www.w3.org/2008/webapps/track/issues/108?changelog 22:18:13 + +1.408.234.aahh 22:18:15 + +1.978.944.aaii 22:18:57 abarth: Can the TAG document their concerns as opposed to playing bring a rock with security goals to TAG. 22:19:36 bhill2: We can wait for them to create a security considerations text or create our own. Their concern is the the CORS approach is fundamentally flawed. 22:20:12 gopal has joined #webappsec 22:20:52 We have to work in the consensus based process as defined by the W3C. 22:21:24 We need to demonstrate that we have addresssed their concerns. 22:21:36 abarth: Why are we discussing the issue in the TAG and not the WG? 22:23:20 Part of the process should be engaging the relevent TAG members in the WG. 22:25:00 bhill2: We can move forward to last call, but it would be good to proactively address the issues that have been brought up. 22:25:19 abarth: We should just create the best spec we know how to create and move foward. 22:26:54 ekr: Create a security considerations section we are happy with. 22:28:14 ACTION to bhill2 to email anne wrt proposed additions to security considerations for CORS re: confused deputy 22:28:14 Sorry, couldn't find user - to 22:28:26 ACTION bhill2 to email anne wrt proposed additions to security considerations for CORS re: confused deputy 22:28:27 Created ACTION-37 - Email anne wrt proposed additions to security considerations for CORS re: confused deputy [on Brad Hill - due 2012-01-10]. 22:29:18 http://lists.w3.org/Archives/Public/public-webappsec/2011Dec/0031.html 22:29:19 CSP for scripts and stylesheets 22:32:02 abarth: There's a general problem with things non CSS being sent to the CSS parser. 22:32:41 We should definitely mention that it is important this is implemented correctly. 22:32:49 Not sure what to do the JSONP issue. 22:33:07 Possibly whitelist directories 22:33:23 Other possibilities are JSON specific. Don't know what the best solution is. 22:34:40 ISSUE how to deal with return-oriented-programming attacks against JSONP interfaces at whitelisted origins 22:35:02 Rajesh has joined #webappsec 22:35:41 Access-Control-Request lowercasing 22:35:54 https://www.w3.org/Bugs/Public/show_bug.cgi?id=15312 22:36:48 bhill2: Don't have the context to discuss this today. Table it for today and discuss on mail list. 22:36:56 http://lists.w3.org/Archives/Public/public-webappsec/2011Dec/0039.html 22:37:01 CSP and ISP rewriting 22:37:53 bhill2: Consensus on the call that this is not a scenario we are going to accomodate. 22:38:28 action: abarth to record that ISPs should not mess with CSP, and if you are worried about this, you should do HTTPS. 22:38:28 Created ACTION-38 - Record that ISPs should not mess with CSP, and if you are worried about this, you should do HTTPS. [on Adam Barth - due 2012-01-10]. 22:39:47 ekr: One more piece of business; How do we get done? 22:40:29 - +1.408.234.aahh 22:40:36 Adding things like this to the agenda because they are alleged technical defects. Once we no longer have defects, we're at 1.0. Is this everyone's concensus? 22:41:01 bhill2: Move to last call once editors are comfortable with that request. 22:41:22 May be a good idea to move more aggressively to last call. 22:42:16 For next call we try and go through all the open issues and resolve them. 22:42:48 -ekr 22:42:51 -[Microsoft] 22:42:52 -krisk 22:42:53 thanks, happy new year 22:43:05 -rrware 22:43:06 -abarth 22:43:08 - +1.978.944.aaii 22:43:08 -gma1 22:43:09 -bhill2 22:43:09 - +1.415.832.aaff 22:43:17 - +1.650.224.aagg 22:43:18 SEC_WASWG()5:00PM has ended 22:43:19 Attendees were +1.650.678.aaaa, ekr, gma1, +1.650.648.aabb, +1.303.229.aacc, bhill2, abarth, +1.408.234.aaee, +1.415.832.aaff, krisk, +1.650.224.aagg, [Microsoft], rrware, 22:43:21 rrware has joined #webappsec 22:43:21 thanks everyone 22:43:21 ... +1.408.234.aahh, +1.978.944.aaii 22:43:24 jrossi has left #webappsec 22:43:42 rrsagent, set logs public-visible 22:43:49 rrsagent, make minutes 22:43:49 I have made the request to generate http://www.w3.org/2012/01/03-webappsec-minutes.html bhill2 23:47:35 bhill2 has joined #webappsec