Re: Securing the security reviews in W3C - how to proceed ?
"Chaals McCathie Nevile" <[email protected]> Fri, 22 Jul 2016 21:32:42 +0200
| Newsgroups | gmane.org.w3c.tag,gmane.spam.detected |
|---|---|
| Organization | Yandex |
| Message-ID | <[email protected]> |
On Fri, 22 Jul 2016 12:27:39 +0200, Martin J. D=C3=BCrst = <[email protected]> wrote: > On 2016/07/22 18:47, Martin J. D=C3=BCrst wrote: >> On 2016/07/21 23:49, Anne van Kesteren wrote: >>> I think increasing the overall security competence and understanding= >>> of the same-origin policy, through self-review and learning, is much= >>> more important than delegating the task to a pool of "experts". Agreed. Especially in a world where we don't have agreed ways to even = measure the expertise of others, One of the things experts *can* help with is precisely that learning. >>> The idea of having "accessibility", "internationalization", and now >>> "security" pillars has proven not to scale Hmm. Expecting them to handle the work has generally not scaled at all = well. On the other hand having them describe best practices has in the long ru= n = turned out to be a good way to scale what expertise we have - providing = a = platform for people to learn from that is also a concrete base for those= = who are or have learned to challenge, build on, and improve. Leading edge efforts such as WAI and i18n have taken many years to produ= ce = their work, with a lot of revision as we learn how to explain things in = = the first place and then how to do so in a way that takes account of the= = continuous changes in our environment. This leads me to the conclusion = that we're not very good teachers of each other, but that it is somethin= g = we do learn to do better over time. >>> It's good to have communities where you can go for help, but >>> making them responsible doesn't really work. >> >> Based on my experience with internationalization, I think both trying= to >> take responsibility for all aspects of your spec AND being able to as= k >> expert groups for help is important. It seems to me you are both saying the same thing, and I agree. There is= = value in a community of experts, but one of the key values is for the = experts to help the rest of us get to a reasonable level of competence, = so = instead of the experts having to continuously explain our beginners' = mistake to us, we can do that amongst ourselves, and ask them to focus o= n = the hard questions. I suspect that also makes the whole thing more fun. While having fun isn= 't = our end goal, if it happens that way we will likely be more productive f= or = longer, and be happier about it, so it's not a bad thing to encourage. (Alternately, we could try to gamify security reviews by making up magic= al = characters you can collect if you find a bug=E2=80=A6 but that sort of t= hing would = never work so it's clearly a silly idea=E2=80=A6) cheers Chaals -- = Charles McCathie Nevile - web standards - CTO Office, Yandex [email protected] - - - Find more at http://yandex.com