js-shield
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Development meeting 20230228


From: Michael McMahon
Subject: Development meeting 20230228
Date: Tue, 28 Feb 2023 12:12:34 -0500
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Icedove/102.7.1

* Grants (Development/Design)
  * NLnet
    - MoU between FSF and you both has been sent out.
    - Michael has questions for Zoë.
* Open Technology Fund - ‘Free and Open Source Software’ Sustainability Fund
    - Still looking at it.
  * HORIZON
    - Still looking at it.
  * Be on the lookout for other grant opportunities.

- Speaking (Development/Design)
  - LibrePlanet 2023 (March 18-19, 2023)
    - https://libreplanet.org/2023/
- Preparing talk. Let Libor know if there are any items that we need to address.
  - SECRYPT 2023 (July 10-12, 2023) Rome, Italy
    - https://secrypt.scitevents.org/
    - Submitted.
  - Other potential conferences
    - 2023-08-05–08-13 DEF CON https://defcon.org/ - Las Vegas, NV
    - 2023-08-05–08-10 Black Hat https://www.blackhat.com/ - Las Vegas, NV

* Manifest V3 (Development)
* Tried testing. There were some issues with Chrome. Will try to fix these issues this week or by mid-march.
  * Let us know if there is anything that we can help with at this point.

* User stats (Development/Design)
  * JShelter user statistics as of 2023-02-28.
    * Chrome users: 3170 (???%) (2023-02-28)
    * Firefox users: 528 (???%) (2023-02-28)
      - Recent spike possibly related to LibrePlanet annoucement.
    * Total known users: 3698
* Uncounted users would include users of Firefox based browsers which do not check each day for browser updates.

* Paper
  * Network error logging (NEL) paper
- The browser can report what the user is doing to a network error collector. The browser reports activity only after receiving from the server. Can report successes and errors. Potential attack surface. If you use a TLS proxy the policy could be a mitm. Being standardized by w3c. If you control part of a website, you can insert the policy. Maybe a shield could be put up to rewrite url entries from Report-To HTTP response headers.

* Next meeting (Development/Design)
  * Development meetings repeating every two weeks from Jan 31st onward.
  * Next meeting: March 21st or 28th?
* No meeting on Tue March 14th (Pi Day). We can schedule a meeting closer to that date.



reply via email to

[Prev in Thread] Current Thread [Next in Thread]