20:59:39 RRSAgent has joined #webappsec 20:59:39 logging to http://www.w3.org/2012/07/03-webappsec-irc 20:59:49 zakim, this is 92794 20:59:49 ok, bhill2; that matches SEC_WASWG()5:00PM 20:59:56 rrsagent, begin 21:00:18 Meeting: WebAppSec Teleconference, 7 Jul 2012 21:00:23 Chair: bhill2, ekr 21:00:38 jeffh has joined #webappsec 21:00:40 Agenda: http://lists.w3.org/Archives/Public/public-webappsec/2012Jul/0003.html 21:00:52 zakim, who is here? 21:00:52 On the phone I see abarth, ccarson, +1.866.317.aaaa, +1.303.229.aabb 21:00:54 On IRC I see jeffh, RRSAgent, Zakim, ccarson, gopal, abarth, gioma1, bhill2, timeless, annevk, trackbot, caribou, odinho 21:00:56 + +1.781.218.aacc 21:00:57 zakim, aabb is bhill2 21:00:58 +bhill2; got it 21:01:27 zakim, aacc is gopal 21:01:27 +gopal; got it 21:01:50 zakim, aaaa is jeffh 21:01:50 +jeffh; got it 21:02:01 +??P11 21:02:57 + +1.408.320.aadd 21:03:03 dhuang3 has joined #webappsec 21:03:17 +tanvi 21:03:36 hm, who has all that bkground noise ? 21:03:51 Scribe: David Huang 21:03:59 ScribeNick: dhuang3 21:04:32 Zakim, who is making noise? 21:04:47 timeless, listening for 14 seconds I could not identify any sounds 21:05:04 +ekr 21:05:10 zakim, aadd is dhuang3 21:05:10 +dhuang3; got it 21:06:39 bhill: updating scribe lists 21:08:05 zakim, ??P11 is gioma1 21:08:05 +gioma1; got it 21:08:24 ekr: minutes except last meeting posted 21:08:49 +[Microsoft] 21:08:50 bhill: approve minutes of previous meeting 21:08:57 jrossi has joined #webappsec 21:09:50 +??P19 21:10:05 adding csp/sandbox discussion to agenda? 21:10:26 uri for actions and issues ? 21:10:28 http://lists.w3.org/Archives/Public/public-webappsec/2012Jul/0003.html 21:10:47 http://www.w3.org/2011/webappsec/track/ 21:10:52 thx 21:11:19 dveditz has joined #webappsec 21:11:49 abarth: action 67 not yet 21:12:15 bhill: action 68 closed, have draft 21:12:40 bhill: action 69, not yet 21:13:49 abarth: action 70-72,58 in agenda 21:14:04 you can close action 58 21:17:14 bhill: any last comment issues on csp? 21:17:14 abarth: working on draft today, no controversial issue 21:19:21 bhill: next issue, how to handle granular list..? 21:19:55 abarth: suggest discussing on mailinglist 21:20:57 abarth: truncation in 1.0 is simple 21:21:39 bhill: next issue, csp and srcdoc 21:22:24 abarth: iframe srcdoc inherits characteristics of parent doc 21:22:52 abarth: CSP is url-based, doesn't notice other ways of loading docs 21:23:09 abarth: might lead to xss holes.. 21:24:45 dveditz?: similar issues in blob url? 21:27:31 abarth: csp can block unknown blobs, other interesting interactions here? 21:28:33 bhill: similar issues in digest uri schemes? 21:29:59 bhill: creating new task 21:30:14 bhill: next issue, obsolete xfo? 21:39:40 need to raise issue on list and cross-post with IETF WebSec 21:39:46 tanvi has joined #webappsec 21:40:09 should UI safety overrride/obsolete XFO, should FO (minus X) be subsumed under CSP directives 21:40:33 should overriding XFO in CSP be a different directive vs. default behavior? 21:42:15 action to bhill2 start cross-IETF/W3C discussion on XFO/FO/UI Safety 21:42:15 Sorry, couldn't find user - to 21:42:34 action bhill2 to start cross-IETF/W3C discussion on XFO/FO/UI Safety 21:42:34 Created ACTION-73 - Start cross-IETF/W3C discussion on XFO/FO/UI Safety [on Brad Hill - due 2012-07-10]. 21:46:06 http://dvcs.w3.org/hg/user-interface-safety/raw-file/25bb022cd7bc/user-interface-safety.html 21:54:30 gopal: encourage developers to contribute more tests suites.. (dhuang: sorry I missed a lot of scribing) 21:54:37 adam is breaking up 21:54:43 jrossi?: need to improve securrity considerations.. 21:56:04 abarth: lacking editor for cors 21:58:19 ...clarifying sandbox/meta tag 21:59:16 should discuss on mailinglist 21:59:26 -jeffh 21:59:27 -ekr 21:59:28 -[Microsoft] 21:59:28 zakim, list attendees 21:59:29 As of this point the attendees have been abarth, ccarson, +1.866.317.aaaa, +1.303.229.aabb, +1.781.218.aacc, bhill2, gopal, jeffh, +1.408.320.aadd, tanvi, ekr, dhuang3, gioma1, 21:59:29 ... [Microsoft] 21:59:29 -abarth 21:59:31 -dhuang3 21:59:32 -gopal 21:59:34 -??P19 21:59:36 -ccarson 21:59:38 -tanvi 21:59:41 -gioma1 21:59:51 rrsagent, set logs public-visible 21:59:56 rrsagent, make minutes 21:59:56 I have made the request to generate http://www.w3.org/2012/07/03-webappsec-minutes.html bhill2 22:00:04 thanks for scribing, david! 22:00:13 -bhill2 22:00:14 SEC_WASWG()5:00PM has ended 22:00:14 Attendees were abarth, ccarson, +1.866.317.aaaa, +1.303.229.aabb, +1.781.218.aacc, bhill2, gopal, jeffh, +1.408.320.aadd, tanvi, ekr, dhuang3, gioma1, [Microsoft] 22:01:29 jeffh has left #webappsec 22:02:37 jeffh has joined #webappsec 22:02:56 jeffh has left #webappsec 22:05:26 equalsJeffH has joined #webappsec 22:06:23 equalsJeffH has joined #webappsec 22:10:10 equalsJeffH has left #webappsec 22:40:10 abarth has joined #webappsec