Re: Securing the security reviews in W3C - how to proceed ?

"Chaals McCathie Nevile" <[email protected]> Fri, 22 Jul 2016 21:32:42 +0200
Newsgroups gmane.org.w3c.tag,gmane.spam.detected
Organization Yandex
Message-ID <[email protected]>
On Fri, 22 Jul 2016 12:27:39 +0200, Martin J. D=C3=BCrst  =

<[email protected]> wrote:

> On 2016/07/22 18:47, Martin J. D=C3=BCrst wrote:
>> On 2016/07/21 23:49, Anne van Kesteren wrote:

>>> I think increasing the overall security competence and understanding=

>>> of the same-origin policy, through self-review and learning, is much=

>>> more important than delegating the task to a pool of "experts".

Agreed. Especially in a world where we don't have agreed ways to even  =

measure the expertise of others,

One of the things experts *can* help with is precisely that learning.

>>> The idea of having "accessibility", "internationalization", and now
>>> "security" pillars has proven not to scale

Hmm. Expecting them to handle the work has generally not scaled at all  =

well.

On the other hand having them describe best practices has in the long ru=
n  =

turned out to be a good way to scale what expertise we have - providing =
a  =

platform for people to learn from that is also a concrete base for those=
  =

who are or have learned to challenge, build on, and improve.

Leading edge efforts such as WAI and i18n have taken many years to produ=
ce  =

their work, with a lot of revision as we learn how to explain things in =
 =

the first place and then how to do so in a way that takes account of the=
  =

continuous changes in our environment. This leads me to the conclusion  =

that we're not very good teachers of each other, but that it is somethin=
g  =

we do learn to do better over time.

>>> It's good to have communities where you can go for help, but
>>> making them responsible doesn't really work.
>>
>> Based on my experience with internationalization, I think both trying=
 to
>> take responsibility for all aspects of your spec AND being able to as=
k
>> expert groups for help is important.

It seems to me you are both saying the same thing, and I agree. There is=
  =

value in a community of experts, but one of the key values is for the  =

experts to help the rest of us get to a reasonable level of competence, =
so  =

instead of the experts having to continuously explain our beginners'  =

mistake to us, we can do that amongst ourselves, and ask them to focus o=
n  =

the hard questions.

I suspect that also makes the whole thing more fun. While having fun isn=
't  =

our end goal, if it happens that way we will likely be more productive f=
or  =

longer, and be happier about it, so it's not a bad thing to encourage.

(Alternately, we could try to gamify security reviews by making up magic=
al  =

characters you can collect if you find a bug=E2=80=A6 but that sort of t=
hing would  =

never work so it's clearly a silly idea=E2=80=A6)

cheers

Chaals

-- =

Charles McCathie Nevile - web standards - CTO Office, Yandex
  [email protected] - - - Find more at http://yandex.com