Re: Securing the security reviews in W3C - how to proceed ?
Yan Zhu <[email protected]> Thu, 21 Jul 2016 11:00:23 -0400
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <CAFDBa1WB5NXgeAMQq5C4myiW=zQFMKs6+OSgmh17UoMKUXa1MA@mail.gmail.com> |
--94eb2c12a048e17a660538269311 Content-Type: text/plain; charset=UTF-8 IIRC, the TAG has/had an informal policy of asking groups to self-review using https://www.w3.org/TR/security-privacy-questionnaire/ before a spec reached TAG review. I would be in favor of making this self-review process mandatory. On Thu, Jul 21, 2016 at 10:49 AM, Anne van Kesteren <[email protected]> wrote: > On Thu, Jul 21, 2016 at 4:34 PM, GALINDO Virginie > <[email protected]> wrote: > > Thanks for jumping in that thread if you believe you can help with > improving security reviews in W3C ! > > I think increasing the overall security competence and understanding > of the same-origin policy, through self-review and learning, is much > more important than delegating the task to a pool of "experts". The > idea of having "accessibility", "internationalization", and now > "security" pillars has proven not to scale and has done more harm than > good. It's good to have communities where you can go for help, but > making them responsible doesn't really work. > > > -- > https://annevankesteren.nl/ > > --94eb2c12a048e17a660538269311 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">IIRC, the TAG has/had an informal policy of asking groups = to self-review using <a href=3D"https://www.w3.org/TR/security-privacy-ques= tionnaire/">https://www.w3.org/TR/security-privacy-questionnaire/</a> befor= e a spec reached TAG review. I would be in favor of making this self-review= process mandatory.=C2=A0</div><div class=3D"gmail_extra"><br><div class=3D= "gmail_quote">On Thu, Jul 21, 2016 at 10:49 AM, Anne van Kesteren <span dir= =3D"ltr"><<a href=3D"mailto:[email protected]" target=3D"_blank">annevk@a= nnevk.nl</a>></span> wrote:<br><blockquote class=3D"gmail_quote" style= =3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span cl= ass=3D"">On Thu, Jul 21, 2016 at 4:34 PM, GALINDO Virginie<br> <<a href=3D"mailto:[email protected]">Virginie.Galindo@gemalt= o.com</a>> wrote:<br> > Thanks for jumping in that thread if you believe you can help with imp= roving security reviews in W3C !<br> <br> </span>I think increasing the overall security competence and understanding= <br> of the same-origin policy, through self-review and learning, is much<br> more important than delegating the task to a pool of "experts". T= he<br> idea of having "accessibility", "internationalization",= and now<br> "security" pillars has proven not to scale and has done more harm= than<br> good. It's good to have communities where you can go for help, but<br> making them responsible doesn't really work.<br> <span class=3D"HOEnZb"><font color=3D"#888888"><br> <br> --<br> <a href=3D"https://annevankesteren.nl/" rel=3D"noreferrer" target=3D"_blank= ">https://annevankesteren.nl/</a><br> <br> </font></span></blockquote></div><br></div> --94eb2c12a048e17a660538269311--