Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ig/security] Add a concrete threat model for the Web to the deliverables. #583

Open
wants to merge 1 commit into
base: gh-pages
Choose a base branch
from

Conversation

jyasskin
Copy link
Member

@jyasskin jyasskin commented Sep 3, 2024

This goes along with Google's comment in the charter's AC review.

<li><a href="https://chromium.googlesource.com/chromium/src/+/master/docs/security/web-platform-security-guidelines.md">Chromium Web Platform Security guidelines</a></li>
<li>The <a href="https://xsleaks.dev/">XS-Leaks Wiki</a></li>
<ul>
</dd>
<dt id="TMG" class="spec">
Threat Modeling guide
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure if the concrete threat model should replace this general guide. If this IG is meant to subsume the Threat Modeling CG, then the guide should definitely remain one of this group's deliverables, but otherwise maybe the CG should be the sole owner, and this group should just be willing to schedule some discussion time for it.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think that there are different things, one more generic and another one tied to the web platform

Comment on lines +201 to +204
<p><b>Potential input documents:</b></p>
<ul>
<li><a href="https://chromium.googlesource.com/chromium/src/+/master/docs/security/web-platform-security-guidelines.md">Chromium Web Platform Security guidelines</a></li>
<li>The <a href="https://xsleaks.dev/">XS-Leaks Wiki</a></li>
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ideally the charter would list a few more input documents from outside of Chromium's orbit. These are just the documents I had handy.

@simoneonofri simoneonofri self-assigned this Sep 12, 2024
@simoneonofri simoneonofri changed the title Add a concrete threat model for the Web to the deliverables. [ig/security] Add a concrete threat model for the Web to the deliverables. Sep 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants