Main Page: Difference between revisions

From Web Security
Bhill2 (talk | contribs)
Vgalindo (talk | contribs)
Undo revision 867 by Khaledomar (talk)
 
(28 intermediate revisions by 5 users not shown)
Line 1: Line 1:
= Web Security Wiki =
Welcome to the wiki of the [http://www.w3.org/Security/ W3C Web Security] related activities.


''Improving standards and implementations to advance the security of the Web.''
This wiki is providing you with


This wiki is open for contributions by all with a W3C account. For discussions, please refer to the [http://lists.w3.org/Archives/Public/public-web-security/ public-web-security mailing list].
* an entry point to each group wiki
* a reference to the important on-going deliverables, gathering efforts of security contributors in W3C


* [http://www.w3.org/Help/Account/Request/Member request a Member account] (use if you work for a W3C member company)
= Entry point to W3C security related wikis =
* [http://www.w3.org/Help/Account/Request/Public request a Public account] (use otherwise)
 
* [http://www.w3.org/Help/Account/MailPassword/ password mailback]
 
* [http://www.w3.org/2011/webappsec/ WebAppSec WG]
* [http://www.w3.org/2012/webcrypto/ WebCrypto WG]
* [http://www.w3.org/2008/xmlsec XML Security WG] (limited activity)
* [http://www.w3.org/Security/wiki/IG Web Security Interest Group]


==Specs to review, groups to watch==


===Specs===
Other important activities are happening on other groups and that may impact the web (security) model
* [http://www.w3.org/html/wg HTML WG]
* [http://www.w3.org/2009/dap Device APIs]
* [http://www.w3.org/2012/sysapps/ SysApp WG]
* [http://www.w3.org/2008/webapps Webapps WG]
* [http://www.w3.org/2011/04/webrtc/ Web Real-Time Communications WG]


Wiki pages containing information about these specifications:
= W3C deliverables to monitor =
Some working draft are currently discussed in those different groups and should require your review and comments :  


* [[Content Security Policy]] ([http://www.w3.org/2011/webappsec/ webappsec]); use the [http://lists.w3.org/Archives/Public/public-web-security/ public-webappsec@w3.org] mailing list for discussion.
* [[XMLHttpRequest]] (webapps)
* [[CORS|CORS and Uniform Messaging Policy]] ([http://www.w3.org/2011/webappsec/ webappsec]); use the [http://lists.w3.org/Archives/Public/public-web-security/ public-webappsec@w3.org] mail list for related discussions
* [[HTML5]] (html)
* [[Websockets]] (webapps)
* [[Anti-Clickjacking Requirements]] ([http://www.w3.org/2011/webappsec/ webappsec]); use the [http://lists.w3.org/Archives/Public/public-web-security/ public-webappsec@w3.org] mailing list for discussion.


===Groups===
* [http://www.w3.org/TR/UISecurity/ User Interface Security Directives for Content Security Policy] at Last Call stage
* [http://www.w3.org/TR/WebCryptoAPI/ Web Crypto API] at Last Call stage
* [http://www.w3.org/TR/CSP11/ Content Security Policy 1.1] at WD draft
* [http://www.w3.org/TR/SRI/ Subresource Integrity] at FPWD stage


* [http://www.w3.org/2011/webappsec/ WebAppSec WG]
= How to contribute ? =
* [http://www.w3.org/2008/webapps Webapps]
You want to be part of this effort related to ''improving standards and implementations to advance the security of the Web''?
* [http://www.w3.org/html/wg HTML WG]
* [http://www.w3.org/2009/dap Device APIs]
* [http://www.w3.org/2008/xmlsec XML Security WG]


===Related Groups to Liaise With===
* join the WG or IG
* contribute to this wiki


* [http://www.ietf.org/ IETF] [http://datatracker.ietf.org/wg/websec/charter/ WebSec Working Group]


== Ongoing issues ==
This wiki is open for contributions by all with a W3C account.
For general discussions, please refer to the [http://lists.w3.org/Archives/Public/public-web-security/ public-web-security mailing list].


* [[Trusted User Interface]]
* [http://www.w3.org/Help/Account/Request/Member request a Member account] (use if you work for a W3C member company)
* [[Same Origin Policy]] and [http://tools.ietf.org/html/draft-ietf-websec-origin Same Origin Policy] by Adam Barth
* [http://www.w3.org/Help/Account/Request/Public request a Public account] (use otherwise)
* [[Cross Site Attacks]]  
* [http://www.w3.org/Help/Account/MailPassword/ password mailback]
* [[Comparison of CORS and UMP]] (Work in progress)


Perhaps this wiki would be handy for thinking thru some security patterns the TAG is discussing under [http://www.w3.org/2001/tag/group/track/issues/31 ISSUE-31 (metadatainURI-31)]...
= Activities =


* [[Ungessable URI]], [[Web Key]], [[Email Confirmation]]
* [Draft Report of WebCrypto Workshop]
* [[Passwords In The Clear]] (maybe not worth bothering; the finding is done, I think)
= Related Groups to Liaise With =


== Meetings ==
* [http://www.ietf.org/ IETF] [http://datatracker.ietf.org/wg/websec/charter/ WebSec Working Group]
* OWASP ?


* [http://esw.w3.org/topic/TPAC_Security_BOF TPAC 2009 security BOF]
Note : you can access the old version of that wiki [https://www.w3.org/Security/wiki/old2014]

Latest revision as of 09:34, 24 September 2015

Welcome to the wiki of the W3C Web Security related activities.

This wiki is providing you with

  • an entry point to each group wiki
  • a reference to the important on-going deliverables, gathering efforts of security contributors in W3C

Entry point to W3C security related wikis


Other important activities are happening on other groups and that may impact the web (security) model

W3C deliverables to monitor

Some working draft are currently discussed in those different groups and should require your review and comments :


How to contribute ?

You want to be part of this effort related to improving standards and implementations to advance the security of the Web?

  • join the WG or IG
  • contribute to this wiki


This wiki is open for contributions by all with a W3C account. For general discussions, please refer to the public-web-security mailing list.

Activities

  • [Draft Report of WebCrypto Workshop]

Related Groups to Liaise With

Note : you can access the old version of that wiki [1]