Main Page
Web Security Wiki
Improving standards and implementations to advance the security of the Web.
This wiki is open for contributions by all with a W3C account. For discussions, please refer to the public-web-security mailing list.
- request a Member account (use if you work for a W3C member company)
- request a Public account (use otherwise)
- password mailback
Specs to review, groups to watch
Specs -- the pages linked here hold notes about the specifications in question:
- XMLHttpRequest (webapps)
- CORS and Uniform Messaging Policy (webapps); use the public-webapps@w3.org mail list for related discussions
- HTML5
- Websockets
Groups:
Related Groups to Liaise With:
Community specifications
This section lists specs (and notes about specs) that don't yet have a formal home.
- Content Security Policy; see also Content Security Policies
- Strict Transport Security (superseded -- now at the IETF WebSec Working Group)
Ongoing issues
- Trusted User Interface
- Same Origin Policy and Same Origin Policy by Adam Barth
- Cross Site Attacks
- Comparison of CORS and UMP (Work in progress)
Perhaps this wiki would be handy for thinking thru some security patterns the TAG is discussing under ISSUE-31 (metadatainURI-31)...
- Ungessable URI, Web Key, Email Confirmation
- Passwords In The Clear (maybe not worth bothering; the finding is done, I think)