Re: [b2g] WebApps - Types of applications

2012-03-26 Thread Scott Wilson
On 26 Mar 2012, at 19:38, lkcl luke wrote: > On Mon, Mar 26, 2012 at 7:30 PM, Scott Wilson > wrote: >> >> On 26 Mar 2012, at 18:57, lkcl luke wrote: >> >>> On Fri, Mar 23, 2012 at 10:12 AM, Scott Wilson >>> wrote: See: http://www.w3.org/TR/widgets-digsig/ >>> >>> well now, scott - that

Re: [b2g] WebApps - Types of applications

2012-03-26 Thread Scott Wilson
On 26 Mar 2012, at 18:57, lkcl luke wrote: > On Fri, Mar 23, 2012 at 10:12 AM, Scott Wilson > wrote: >> See: http://www.w3.org/TR/widgets-digsig/ > > well now, scott - that is veeery interesting, and incredibly useful, > because it is *exactly* the same thing - bar the file-formats - that > all

about:cache shows sensitive info from memory even with HTTPS and headers set to no-store

2012-03-26 Thread StopEmailSpam StopEmailSpam
I'm building a web app, I have a valid SSL cert and I'm settings my headers to no-store on my web pages. But, my web app's sensitive https data is visable through visiting "about:cache" and clicking to review the device memory. Even after the web application is logged out and the web app's tab is

[GSoC Student] User-Specified Content Security Policy Project

2012-03-26 Thread Chetan Bansal
Hi, I am Chetan Bansal, a 4th year undergraduate student at BITS Pilani University, India. I wish to apply to Mozilla for the Google Summer of Code '12. I have successfully participated in GSoC twice earlier, in 2009 and 2010, working with the GenMapp (Wikipathways) group. Last summer, I worke

Re: WebApps - Types of applications

2012-03-26 Thread Scott Wilson
On 23 Mar 2012, at 08:51, JOSE MANUEL CANTERA FONSECA wrote: > > > El 23/03/12 07:45, "Lucas Adamski" escribió: > >> == Goal == >> Determine a baseline for the different types of applications in the B2G >> app ecosystem. >> >> We are not going to evaluate operating system level issues (such

about:cache shows sensitive info from memory even with HTTPS and headers set to no-store

2012-03-26 Thread StopEmailSpam StopEmailSpam
I'm building a web page and have a valid SSL cert and my headers set to no-store But, about:cache my web page's data even after the application is logged out and the web app's tab is closed (i.e. other tabs and the browser remain open.) Any ideas on what I might be doing wrong? Thank you -SR (P

Suggestion to improve security when using an input form in an iframe

2012-03-26 Thread Karl-Oskar Lundin
When highlighting an input form in an iframe my suggestions is to change the URL in the address bar of the web browser to the iframes URL. This way the user can easily control if the iframe is legitimate or not and also control if SSL is used or not in the iframe. When the input form loses focus t

Re: [b2g] WebApps - Types of applications

2012-03-26 Thread Lucas Adamski
On 3/26/2012 5:47 AM, Paul Theriault wrote: > >>> What do you mean by 'Code Enumerated in the Manifest'? >> Unless this has changed recently, I believe we are using appcache for >> installable apps. Appcache requires a manifest >> that contains an explicit list of assets to assure they can be cac

Re: WebApps - Types of applications

2012-03-26 Thread Lucas Adamski
On 3/24/2012 1:27 AM, ianG wrote: >> === Web pages === >> Description: A normal web page can request access to a certain set of >> WebAPIs. >> >> Use cases: Web pages would like to perform functions historically limited to >> plugins or other binary browser >> extensions. They might want to ca

Re: [Respond by 30-Mar]Click To Play Plug-Ins

2012-03-26 Thread Florian Weimer
* Curtis Koenig: > The security team is preparing for a review of Opt-in Activation for > Plugins, in early April. Given that there has been lots of public > discussion of this item it has been decided to try and get another > public review of the feature page and patches prior to the review on >

Re: [Respond by 30-Mar]Click To Play Plug-Ins

2012-03-26 Thread Martijn
On Mon, Mar 26, 2012 at 9:39 AM, Henri Sivonen wrote: > If I chose "Always enable Flash Player on this site" on YouTube, I'd > expect the setting to affect the http://www.youtube.com/ as the > top-level origin at least. Not sure if it should enable YouTube embeds > on other origins. In my opinion

Re: [b2g] WebApps - Types of applications

2012-03-26 Thread Paul Theriault
What do you mean by 'Code Enumerated in the Manifest'? Unless this has changed recently, I believe we are using appcache for installable apps. Appcache requires a manifest that contains an explicit list of assets to assure they can be cached locally and that the app will work offline and be

Re: [Respond by 30-Mar]Click To Play Plug-Ins

2012-03-26 Thread Henri Sivonen
On Mon, Mar 26, 2012 at 3:24 PM, ianG wrote: > I'm not sure think the average user really understands any of the above. >  Java?  Flash? It seems to me (on an anecdotal level) that users are pretty aware of Flash. Users who have had to install Java to use their bank know about Java. Of course, I

Re: [Respond by 30-Mar]Click To Play Plug-Ins

2012-03-26 Thread ianG
On 26/03/12 18:39 PM, Henri Sivonen wrote: On Fri, Mar 23, 2012 at 9:19 PM, Curtis Koenig wrote: Feature Page: https://wiki.mozilla.org/Opt-in_activation_for_plugins That pages says: Optional requirements Manage plugin run settings on a per-site basis Control plugins on a per-plug

Re: [Respond by 30-Mar]Click To Play Plug-Ins

2012-03-26 Thread Henri Sivonen
On Fri, Mar 23, 2012 at 9:19 PM, Curtis Koenig wrote: > Feature Page: https://wiki.mozilla.org/Opt-in_activation_for_plugins That pages says: > Optional requirements > > Manage plugin run settings on a per-site basis > Control plugins on a per-plugin basis for a given site > Mitigate