Re: Publishing From-Origin Proposal as FPWD

2011-07-06 Thread Arthur Barstow
ehalf Of Bjoern Hoehrmann Sent: Tuesday, July 05, 2011 4:38 PM To: Marcos Caceres Cc: WebApps WG; public-web-secur...@w3.org Subject: Re: Publishing From-Origin Proposal as FPWD * Marcos Caceres wrote: On Tue, Jul 5, 2011 at 5:50 PM, Hill, Brad wrote: I feel that the goals of this draft are either in

Re: Publishing From-Origin Proposal as FPWD

2011-07-06 Thread Anne van Kesteren
On Tue, 05 Jul 2011 17:50:57 +0200, Hill, Brad wrote: I feel that the goals of this draft are either inconsistent with the basic architecture of the web, cannot be meaningfully accomplished by the proposed mechanism, or both, and I haven't seen any discussion of these concerns yet. It wo

RE: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread Hill, Brad
u...@w3.org] On Behalf Of Bjoern Hoehrmann Sent: Tuesday, July 05, 2011 4:38 PM To: Marcos Caceres Cc: WebApps WG; public-web-secur...@w3.org Subject: Re: Publishing From-Origin Proposal as FPWD * Marcos Caceres wrote: >On Tue, Jul 5, 2011 at 5:50 PM, Hill, Brad wrote: >> I feel that the

Re: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread Bjoern Hoehrmann
* Marcos Caceres wrote: >On Tue, Jul 5, 2011 at 5:50 PM, Hill, Brad wrote: >> I feel that the goals of this draft are either inconsistent with the >> basic architecture of the web, cannot be meaningfully accomplished >> by the proposed mechanism, or both, and I haven't seen any discussion >> of th

Re: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread Marcos Caceres
On Tue, Jul 5, 2011 at 9:12 PM, David Singer wrote: > > On Jul 5, 2011, at 8:57 , Marcos Caceres wrote: > >> Hi Brad, >> >> On Tue, Jul 5, 2011 at 5:50 PM, Hill, Brad wrote: >>> Well, my disagreement is not with its content; I think we should not move >>> forward with this spec at all. >>> >>> I

Re: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread David Singer
On Jul 5, 2011, at 8:57 , Marcos Caceres wrote: > Hi Brad, > > On Tue, Jul 5, 2011 at 5:50 PM, Hill, Brad wrote: >> Well, my disagreement is not with its content; I think we should not move >> forward with this spec at all. >> >> I feel that the goals of this draft are either inconsistent wit

Re: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread Marcos Caceres
Hi Brad, On Tue, Jul 5, 2011 at 5:50 PM, Hill, Brad wrote: > Well, my disagreement is not with its content; I think we should not move > forward with this spec at all. > > I feel that the goals of this draft are either inconsistent with the basic > architecture of the web, cannot be meaningfull

RE: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread Hill, Brad
x27;t seen any discussion of these concerns yet. -Brad -Original Message- From: Arthur Barstow [mailto:art.bars...@nokia.com] Sent: Tuesday, July 05, 2011 7:30 AM To: Hill, Brad; Anne van Kesteren Cc: WebApps WG; public-web-secur...@w3.org; Daniel Veditz Subject: Re: Publishing From-O

Re: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread Anne van Kesteren
On Tue, 05 Jul 2011 16:30:26 +0200, Arthur Barstow wrote: Anne - please add some text re the consensus of the contents point and then I'll start the CfC. http://dvcs.w3.org/hg/from-origin/raw-file/tip/Overview.html Now has "The contents of this document do not necessarily reflect the cons

Re: Publishing From-Origin Proposal as FPWD

2011-07-05 Thread Arthur Barstow
Hi Brad, Anne, As I mentioned in [1], I think there is sufficient support for WebApps to publish this spec as a FPWD and I will start a Call for Consensus to more formally determine WebApps' level of support. A WG may publish a FPWD without consensus on the _contents_ of the spec. The Status

RE: Publishing From-Origin Proposal as FPWD

2011-07-01 Thread Hill, Brad
The new WebAppSec WG charter draft does include a deliverable for secure mashups built with cross-domain framing, with the specific intent to put forward a proposal for anti-clickjacking in this space. However, I have concerns with nearly every aspect of this draft. First, I am concerned

Re: Publishing From-Origin Proposal as FPWD

2011-07-01 Thread Arthur Barstow
On 6/30/11 10:31 PM, ext Daniel Veditz wrote: On 6/30/11 9:31 AM, Maciej Stachowiak wrote: On Jun 30, 2011, at 7:22 AM, Anne van Kesteren wrote: (Added public-web-security because of the potential for doing this in CSP instead. Though that would require a slight change of scope for CSP, which I

Re: Publishing From-Origin Proposal as FPWD

2011-06-30 Thread Daniel Veditz
On 6/30/11 9:31 AM, Maciej Stachowiak wrote: > > On Jun 30, 2011, at 7:22 AM, Anne van Kesteren wrote: >> (Added public-web-security because of the potential for doing >> this in CSP instead. Though that would require a slight change >> of scope for CSP, which I'm not sure is actually desirable.)

Re: Publishing From-Origin Proposal as FPWD

2011-06-30 Thread Maciej Stachowiak
On Jun 30, 2011, at 7:22 AM, Anne van Kesteren wrote: > Hi hi, > > Is there anyone who has objections against publishing > http://dvcs.w3.org/hg/from-origin/raw-file/tip/Overview.html as a FPWD. The > idea is mainly to gather more feedback to see if there is any interest in > taking this forw