W3C Workshop Secure the Web Forward

Driving developer awareness and adoption of Web security standards & practices

September 26-28, 2023 - Virtual

Presented by W3C, OpenSSF, OWASP, OpenJS

Parsoa Khorsand

Live sessions

Three live sessions were scheduled on 26-27-28 September 2023 to discuss selected position papers and converge on a common understanding of whether and how things may progress from a standardization perspective.

The calls were open to all invited workshop participants.

Discussion notes for the live sessions are available.

Familiarity with selected position papers was recommended. Presentations of the papers during the live sessions were short. We rather asked participants to take an active role and help shape next steps for each of the topics.

To help guide next steps, the program committee encourages you to capture needs, questions and suggestions for standardization work linked to the topics discussed during the live sessions through issues in the w3c/secure-the-web-workshop GitHub repository

Live session 1: Supply Chain Security

When: - (see local time conversion)
See discussion notes.

Live session 2: JavaScript Security

When: - (see local time conversion)
See discussion notes.

  • Introduction - Setting the context
  • Hardening JavaScript - paper presentations and quick Q&A
    Applying Hardened Javascript to supply chain security for a proactive approach (Zbyszek Tenerowicz)
    JavaScript realms used to bypass and eliminate web apps security tools - A problem with a WIP solution (Gal Weizman)
  • Open discussion on hardening Javascript
  • Break
  • Cookies - paper presentation and quick Q&A
    Open discussion on cookies and JavaScript security (Artur Janc)
  • Open discussion on cookies and JavaScript security
  • Next steps

Live session 3: Developer Awareness

When: - (see local time conversion)
See discussion notes.

  • Introduction - Setting the context
  • Paper presentations and quick Q&A
    Can securing jQuery help secure the Web forward? (Tobie Langel)
    Documentation for web security education (Florian Scholz)
    Roadmap planning for a JavaScript security framework (Joe Sepi, Ben Sternthal)
  • Break
  • Open discussion
  • Concluding the workshop