Re: Securing the security reviews in W3C - how to proceed ?

Yan Zhu <[email protected]> Thu, 21 Jul 2016 11:00:23 -0400
Newsgroups gmane.org.w3c.tag
Message-ID <CAFDBa1WB5NXgeAMQq5C4myiW=zQFMKs6+OSgmh17UoMKUXa1MA@mail.gmail.com>
--94eb2c12a048e17a660538269311
Content-Type: text/plain; charset=UTF-8

IIRC, the TAG has/had an informal policy of asking groups to self-review
using https://www.w3.org/TR/security-privacy-questionnaire/ before a spec
reached TAG review. I would be in favor of making this self-review process
mandatory.

On Thu, Jul 21, 2016 at 10:49 AM, Anne van Kesteren <[email protected]>
wrote:

> On Thu, Jul 21, 2016 at 4:34 PM, GALINDO Virginie
> <[email protected]> wrote:
> > Thanks for jumping in that thread if you believe you can help with
> improving security reviews in W3C !
>
> I think increasing the overall security competence and understanding
> of the same-origin policy, through self-review and learning, is much
> more important than delegating the task to a pool of "experts". The
> idea of having "accessibility", "internationalization", and now
> "security" pillars has proven not to scale and has done more harm than
> good. It's good to have communities where you can go for help, but
> making them responsible doesn't really work.
>
>
> --
> https://annevankesteren.nl/
>
>

--94eb2c12a048e17a660538269311
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">IIRC, the TAG has/had an informal policy of asking groups =
to self-review using <a href=3D"https://www.w3.org/TR/security-privacy-ques=
tionnaire/">https://www.w3.org/TR/security-privacy-questionnaire/</a> befor=
e a spec reached TAG review. I would be in favor of making this self-review=
 process mandatory.=C2=A0</div><div class=3D"gmail_extra"><br><div class=3D=
"gmail_quote">On Thu, Jul 21, 2016 at 10:49 AM, Anne van Kesteren <span dir=
=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">annevk@a=
nnevk.nl</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" style=
=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span cl=
ass=3D"">On Thu, Jul 21, 2016 at 4:34 PM, GALINDO Virginie<br>
&lt;<a href=3D"mailto:[email protected]">Virginie.Galindo@gemalt=
o.com</a>&gt; wrote:<br>
&gt; Thanks for jumping in that thread if you believe you can help with imp=
roving security reviews in W3C !<br>
<br>
</span>I think increasing the overall security competence and understanding=
<br>
of the same-origin policy, through self-review and learning, is much<br>
more important than delegating the task to a pool of &quot;experts&quot;. T=
he<br>
idea of having &quot;accessibility&quot;, &quot;internationalization&quot;,=
 and now<br>
&quot;security&quot; pillars has proven not to scale and has done more harm=
 than<br>
good. It&#39;s good to have communities where you can go for help, but<br>
making them responsible doesn&#39;t really work.<br>
<span class=3D"HOEnZb"><font color=3D"#888888"><br>
<br>
--<br>
<a href=3D"https://annevankesteren.nl/" rel=3D"noreferrer" target=3D"_blank=
">https://annevankesteren.nl/</a><br>
<br>
</font></span></blockquote></div><br></div>

--94eb2c12a048e17a660538269311--