Re: [b2g] Privacy concerns with navigator.pay

2012-08-17 Thread Raymond Forbes
We have performed a security review of navigator.pay and dchan and I performed a security code review. We have not performed a privacy review as of yet but I was just assigned a bug to set one up. -Raymond - Original Message - From: "Jonas Sicking" To: "DANIEL JESUS COLOMA BAIGES" Cc

More OpenWebApps/B2G Security Model

2012-03-30 Thread Raymond Forbes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, One aspect of the security model that I wanted to discuss is where in the implementation this security is applied. First, some assumptions. a) B2G is using OpenWebApps as defined by the OWA standard. b) these apps should run the same no matte

Receipt Generation Service

2012-03-28 Thread Raymond Forbes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, We are in the process of defining and review the process we use for generating and revoking receipts. This is a complicated process that involves signing with a Hardware Security Module. Please take a look at the spec that we have so far and