19 Jan 2017


See also: IRC log


virginie, weiler, kepeng, tara
Virginie Galindo, Kapeng Li, Ryan Ware


<virginie> hello

<virginie> +present

I can try to scribe but expect many mistakes!

<weiler> scribenick: tara


Charter status

Charter has been approved.

Now renewed.

<virginie> https://www.w3.org/2011/07/security-ig-charter.html

Link to updated charter above.

Three focuses of effort identified in charter

One main challenge is critical mass of contributers who have security skills

Kepeng: plan some contributions soon - inputs on security best practices
... may have internal materials to share with group but not immediately

Tara: joined to help PING (privacy IG) keep in sync with security IG

<scribe> Agenda: security reviews

Had some discussions on reviews; Sam as staff contact provided input

Sam gave guidance from IETF process

Sam: agreed to review remote playback API

Review not yet complete; expects to complete

WebSecApp group - managing reviews?

Reviews owned by TAG and WebAppSec - for security and privacy

<virginie> https://www.w3.org/TR/security-privacy-questionnaire/

Questionnaire is not being maintained; Mike West does not have time to work on this (other demands)

On PING aspects - need to coordinate these aspects

Requests out to groups that are using this questionnaire for feedback; work remains

Discussions with TAG provided some input

<scribe> Agenda: News from W3C on security features

INot going to be addressed in this call

Will need to monitor this, ongoing

Kepeng: Q on wiki -- how do we want to maintain this page? Use old or new one? Need to port content?

<virginie> old wiki page : https://www.w3.org/Security/wiki/IG

Virginie: old material needs to be marked as deprecated

<weiler> history of that page says that wendy went through with a big red pen once already.

<virginie> old material is archived here : v

<virginie> https://www.w3.org/Security/wiki/IG/archive

Adding comment from Agenda: Discussion on recent breaches - also deferred

Should use wiki page for indicating who has agreed to manage reviews

Can have links to press articles - activities for focus of IG

Kepeng: in future, can update wiki page (e.g., conf call information, links to documents such as questionnaire)

Can have another call in a month

Thanks all around!

Next meeting - want to accommodate Ryan

<weiler> chairs: kepeng, virginie

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.148 (CVS log)
$Date: 2017/01/19 15:26:19 $

Scribe.perl diagnostic output

[Delete this section before finalizing the minutes.]
This is scribe.perl Revision: 1.148  of Date: 2016/10/11 12:55:14  
Check for newer version at http://dev.w3.org/cvsweb/~checkout~/2002/scribe/

Guessing input format: RRSAgent_Text_Format (score 1.00)

Succeeded: s/Dieter/Mike West/
Found ScribeNick: tara
Inferring Scribes: tara

WARNING: No "Topic:" lines found.

Present: virginie weiler kepeng tara

WARNING: No meeting title found!
You should specify the meeting title like this:
<dbooth> Meeting: Weekly Baking Club Meeting

Agenda: https://lists.w3.org/Archives/Public/public-web-security/2017Jan/0002.html
Got date from IRC log name: 19 Jan 2017
Guessing minutes URL: http://www.w3.org/2017/01/19-websec-minutes.html
People with action items: 

WARNING: Input appears to use implicit continuation lines.
You may need the "-implicitContinuations" option.

WARNING: No "Topic: ..." lines found!  
Resulting HTML may have an empty (invalid) <ol>...</ol>.

Explanation: "Topic: ..." lines are used to indicate the start of 
new discussion topics or agenda items, such as:
<dbooth> Topic: Review of Amy's report

[End of scribe.perl diagnostic output]