Re: removing keygen from HTML
Harry Halpin <[email protected]> Wed, 8 Jun 2016 02:32:51 -1000
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <CAE1ny+6oWUX3yED4t4A5Ye7P_MM3SCBJOfdGxvKhUha-taX6Ww@mail.gmail.com> |
--001a1146cfa00dd5350534c38137 Content-Type: text/plain; charset=UTF-8 On Tue, May 31, 2016 at 6:31 AM, Chaals McCathie Nevile < [email protected]> wrote: > On Tue, 31 May 2016 16:40:30 +0200, Harry Halpin <[email protected]> > wrote: > > On Tue, May 31, 2016 at 3:43 AM, Daniel Appelquist <[email protected]> wrote: >> >> Hi Folks - the TAG (in the person of Travis) has written on this topic: >>> >>> https://w3ctag.github.io/client-certificates/#replacing-keygen >>> >>> As noted, it represents the rough consensus of the TAG on this issue. >>> >> > As I read that, in relation to the question facing the Web Platform group > for the HTML spec: > 1) It doesn't present any urgency to remove keygen, noting that there is > not a replacement available now. > The urgency is that <keygen> as it stands violates SOP and so user privacy (details here - https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/pX5NbX0Xack - although finger-printing avoidance is nearly impossible). However, given that TimBL and a few others on this list use <keygen> in their programming projects, it seems the polite thing to do is not to deprecate it until Web Authentication is ready by end of the year despite the security/privacy concerns. That should at least give TimBL and others time to update their code. > 2) I don't know how rough that consensus is. Multiplying rough consensus > by rough consensus can quickly get to "a minority opinion". > > One could argue to keep <keygen> enabled till when Web Authentication API >> is in browsers. >> > > Which would have a critical impact on our current question - should we > remove it *now*? > Given that Chrome has removed it and Mozilla has said they will remove it, it seems not to make much sense to keep it in the HTML spec. > > Also, as <keygen> is currently non-interoperable and specified in only one >> browser >> > > As far as I can see it works in Safari as well. Is my simplistic testing > giving a false positive, or does it work? > Safari in my experience tends to policy not to comment on future work. Feel free to ask them. However, one browser probably does not mean it should stay in the HTML spec, particularly after Mozilla drops it. You can ask Mozilla for their timeline. > > On Tue, 31 May 2016 at 13:33 Eric Mill <[email protected]> wrote: >>> >>> The original email said: "Since the TAG, or its members, appear to have >>>> opinions about our spec, we'd be grateful to hear them." It'd be most >>>> productive for this thread's discussion to at least be initiated by a >>>> member of the TAG. >>>> >>> > To be fair, I understand the nature of this mailing list, and while I > addressed my comments prmiarily to the TAG I am grateful for others giving > input too. > Given that the TAG sometimes is not aware of all the work happening in W3C, it seemed to make sense to chime in with the Web Authentication timeline. > > cheers > > Chaals > > > -- > Charles McCathie Nevile - web standards - CTO Office, Yandex > [email protected] - - - Find more at http://yandex.com > --001a1146cfa00dd5350534c38137 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo= te">On Tue, May 31, 2016 at 6:31 AM, Chaals McCathie Nevile <span dir=3D"lt= r"><<a href=3D"mailto:[email protected]" target=3D"_blank">chaals@ya= ndex-team.ru</a>></span> wrote:<br><blockquote class=3D"gmail_quote" sty= le=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddi= ng-left:1ex"><span class=3D"">On Tue, 31 May 2016 16:40:30 +0200, Harry Hal= pin <<a href=3D"mailto:[email protected]" target=3D"_blank">hhalpin@ib= iblio.org</a>> wrote:<br> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"> On Tue, May 31, 2016 at 3:43 AM, Daniel Appelquist <<a href=3D"mailto:da= [email protected]" target=3D"_blank">[email protected]</a>> wrote:<br> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"> Hi Folks - the TAG (in the person of Travis) has written on this topic:<br> <br> <a href=3D"https://w3ctag.github.io/client-certificates/#replacing-keygen" = rel=3D"noreferrer" target=3D"_blank">https://w3ctag.github.io/client-certif= icates/#replacing-keygen</a><br> <br> As noted, it represents the rough consensus of the TAG on this issue.<br> </blockquote></blockquote> <br></span> As I read that, in relation to the question facing the Web Platform group f= or the HTML spec:<br> =C2=A01) It doesn't present any urgency to remove keygen, noting that t= here is not a replacement available now.<br></blockquote><div><br></div><di= v>The urgency is that <keygen> as it stands violates SOP and so user = privacy (details here - <a href=3D"https://groups.google.com/a/chromium.org= /forum/#%21topic/blink-dev/pX5NbX0Xack" target=3D"_blank">https://groups.go= ogle.com/a/chromium.org/forum/#!topic/blink-dev/pX5NbX0Xack</a> - although = finger-printing avoidance is nearly impossible). However, given that TimBL = and a few others on this list use <keygen> in their programming proje= cts, it seems the polite thing to do is not to deprecate it until Web Authe= ntication is ready by end of the year despite the security/privacy concerns= . That should at least give TimBL and others time to update their code. <br= ><br>=C2=A0<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px = 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> =C2=A02) I don't know how rough that consensus is. Multiplying rough co= nsensus by rough consensus can quickly get to "a minority opinion"= ;.<span class=3D""><br> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"> One could argue to keep <keygen> enabled till when Web Authentication= API<br> is in browsers.<br> </blockquote> <br></span> Which would have a critical impact on our current question - should we remo= ve it *now*?<span class=3D""><br></span></blockquote><div><br></div><div>Gi= ven that Chrome has removed it and Mozilla has said they will remove it, it= seems not to make much sense to keep it in the HTML spec. <br>=C2=A0<br></= div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bor= der-left:1px solid rgb(204,204,204);padding-left:1ex"><span class=3D""> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"> Also, as <keygen> is currently non-interoperable and specified in onl= y one browser<br> </blockquote> <br></span> As far as I can see it works in Safari as well. Is my simplistic testing gi= ving a false positive, or does it work?<span class=3D""><br></span></blockq= uote><div><br></div><div>Safari in my experience tends to policy not to com= ment on future work. Feel free to ask them. However, one browser probably d= oes not mean it should stay in the HTML spec, particularly after Mozilla dr= ops it. You can ask Mozilla for their timeline.=C2=A0 <br></div><blockquote= class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px so= lid rgb(204,204,204);padding-left:1ex"><span class=3D""> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"><blockquote class=3D"gmai= l_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,20= 4,204);padding-left:1ex"> On Tue, 31 May 2016 at 13:33 Eric Mill <<a href=3D"mailto:eric@konklone.= com" target=3D"_blank">[email protected]</a>> wrote:<br> <br> <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"> The original email said: "Since the TAG, or its members, appear to hav= e<br> opinions about our spec, we'd be grateful to hear them." It'd = be most<br> productive for this thread's discussion to at least be initiated by a<b= r> member of the TAG.<br> </blockquote></blockquote></blockquote> <br></span> To be fair, I understand the nature of this mailing list, and while I addre= ssed my comments prmiarily to the TAG I am grateful for others giving input= too.<br></blockquote><div><br></div><div>Given that the TAG sometimes is n= ot aware of all the work happening in W3C, it seemed to make sense to chime= in with the Web Authentication timeline. <br></div><blockquote class=3D"gm= ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,= 204,204);padding-left:1ex"> <br> cheers<span class=3D""><font color=3D"#888888"><br> <br> Chaals</font></span><div class=3D""><div class=3D"h5"><br> <br> -- <br> Charles McCathie Nevile - web standards - CTO Office, Yandex<br> =C2=A0<a href=3D"mailto:[email protected]" target=3D"_blank">chaals@yan= dex-team.ru</a> - - - Find more at <a href=3D"http://yandex.com" rel=3D"nor= eferrer" target=3D"_blank">http://yandex.com</a><br> </div></div></blockquote></div><br></div></div> --001a1146cfa00dd5350534c38137--