Confirmed users, Bureaucrats and Sysops emeriti
3,599
edits
m (→Alpha 2) |
m (→Security: SSL) |
||
| Line 88: | Line 88: | ||
=== Security: SSL === | === Security: SSL === | ||
* beltzner attended a [http://www.w3.org/2005/Security/usability-ws/program W3C workshop on "Usability and Web Authentication"] last week (you can check out his [[Papers:Sending_the_Right_Signals|position paper]] and [http://people.mozilla.org/~beltzner/w3cpresentation/sending-the-right-signals.html presentation]) | * beltzner attended a [http://www.w3.org/2005/Security/usability-ws/program W3C workshop on "Usability and Web Authentication"] last week (you can check out his [[Papers:Sending_the_Right_Signals|position paper]] and [http://people.mozilla.org/~beltzner/w3cpresentation/sending-the-right-signals.html presentation] (big, flash, sorry!)) | ||
** most plausible suggestions for Firefox2 timeframe were Google Safe Browsing, some form of heuristic detection based on browsing history and bookmarks, use of <browsermessage> notification, ''potentially'' a mechanism for disabling JS and other technologies that assist spoofing on SSL signin pages, and APIs to allow easy integration of third party tools for security | ** most plausible suggestions for Firefox2 timeframe were Google Safe Browsing, some form of heuristic detection based on browsing history and bookmarks, use of <browsermessage> notification, ''potentially'' a mechanism for disabling JS and other technologies that assist spoofing on SSL signin pages, and APIs to allow easy integration of third party tools for security | ||
** W3C will be producing notes and summary soon, I'll link to that as we get it | ** W3C will be producing notes and summary soon, I'll link to that as we get it | ||