[widgets] viewmodes spec

View: New views
5 Messages — Rating Filter:   Alert me  

[widgets] viewmodes spec

by David Rogers-5 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.

Hi there,

 

At the last widgets call I agreed to ask OMTP BONDI members if there was any feedback on viewmodes. We didn’t receive a lot of views but one thing I raised was that as far as I can tell, there is no text to cover off invisible widgets or widgets of, for example height and width 1x1. There may be a valid reason for someone to have an invisible widget but there are still some abuse scenarios – for example, if someone created a transparent widget that then maximises in front of your payment application just as you go to enter your PIN or password it could be a major issue.

 

I’m not sure that anyone has started work on any widget security guidelines?

 

Thanks,

 

 

David.

 

 

David Rogers
OMTP
Director of External Relations

 


Parent Message unknown FW: [widgets] viewmodes spec

by David Rogers-5 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Some parts of this message have been removed. Learn more about Nabble's security policy.

Hi Art and Marcos,

 

I didn’t see this point discussed in the last widgets meeting minutes. Do you know if anybody has started work on any security guidelines for widgets? I noticed that in the “Web Security Context: User Interface Guidelines”, for example this requirement[1] there may be some conflict with widgets / potential to put requirements there for the item below and others?

 

Thanks,

 

 

David.

 

[1] http://www.w3.org/TR/wsc-ui/#keepchromevisible-goodpractice

 

From: public-webapps-request@... [mailto:public-webapps-request@...] On Behalf Of David Rogers
Sent: 22 October 2009 11:52
To: public-webapps@...
Cc: Barstow Art (Nokia-CIC/Boston)
Subject: [widgets] viewmodes spec

 

Hi there,

 

At the last widgets call I agreed to ask OMTP BONDI members if there was any feedback on viewmodes. We didn’t receive a lot of views but one thing I raised was that as far as I can tell, there is no text to cover off invisible widgets or widgets of, for example height and width 1x1. There may be a valid reason for someone to have an invisible widget but there are still some abuse scenarios – for example, if someone created a transparent widget that then maximises in front of your payment application just as you go to enter your PIN or password it could be a major issue.

 

I’m not sure that anyone has started work on any widget security guidelines?

 

Thanks,

 

 

David.

 

 

David Rogers
OMTP
Director of External Relations

 


[widgets] Security Guidelines for Widgets? [Was: Re: [widgets] viewmodes spec]

by Arthur Barstow :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Oct 26, 2009, at 5:23 AM, ext David Rogers wrote:

> Do you know if anybody has started work on any security guidelines  
> for widgets?

I am not aware of any such work.

-Regards, Art Barstow

> I noticed that in the “Web Security Context: User Interface  
> Guidelines”, for example this requirement[1] there may be some  
> conflict with widgets / potential to put requirements there for the  
> item below and others?
>
> Thanks,
>
> David.
>
> [1] http://www.w3.org/TR/wsc-ui/#keepchromevisible-goodpractice


Re: [widgets] Security Guidelines for Widgets? [Was: Re: [widgets] viewmodes spec]

by Marcos Caceres-3 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

On Tue, Oct 27, 2009 at 4:26 PM, Arthur Barstow <Art.Barstow@...> wrote:
> On Oct 26, 2009, at 5:23 AM, ext David Rogers wrote:
>
>> Do you know if anybody has started work on any security guidelines for
>> widgets?
>
> I am not aware of any such work.
>

Please see:
http://lists.w3.org/Archives/Public/public-webapps/2009OctDec/0364.html

This is now in the spec. I've requested people contribute some text.



--
Marcos Caceres
http://datadriven.com.au


Re: FW: [widgets] viewmodes spec

by Marcos Caceres-3 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

2009/10/26 David Rogers <david.rogers@...>:
> Hi Art and Marcos,
>
>
>
> I didn’t see this point discussed in the last widgets meeting minutes. Do you know if anybody has started work on any security guidelines for widgets? I noticed that in the “Web Security Context: User Interface Guidelines”, for example this requirement[1] there may be some conflict with widgets / potential to put requirements there for the item below and others?
>

We have not yet started work on this. We could certainly add a
security considerations section to one the view mode specs (as we have
done with P&C and with Dig Sig). Please feel free to contribute some
tests.

--
Marcos Caceres
http://datadriven.com.au