00:04
<TabAtkins>
othermaciej: Huh, must have missed 89 in all the flurry. Yeah, I'll write up that one. I'll also, reluctantly, write up a counter to 92, since Shelley's hell-bent on smuggling in @summary for no reason.
00:07
<othermaciej>
TabAtkins: Shelley did leave the group, but she did not withdraw her Change Proposals
00:08
<TabAtkins>
Kk. The deadline for 89 is the 20th, and 92 is, what, the 16th?
00:15
<annevk>
othermaciej, browser extensions are not a use case
00:16
<othermaciej>
annevk: if we add an API for this (which we'd like to), it would be nice to use the same one that will be part of the standard WEb platform
00:16
<othermaciej>
annevk: so it would be good to have a name etc
00:16
<annevk>
it seems the API they have would work differently
00:17
<annevk>
as I don't think Amazon uses the right response headers
00:17
<annevk>
having said that, I haven't changed much because I've been thinking about whether we can still simplify things
00:17
<annevk>
header names, withCredentials, etc.
00:18
<annevk>
but maybe changing details around is not worth it and we should let SPDY do the header name compression
00:24
<annevk>
aah, WebSRT comments on public-html
00:25
<annevk>
hadn't noticed them until now
00:26
<othermaciej>
and in bugzilla!
00:29
<Philip`>
"the correspondence isn't perfect; it's probably close enough that a CSS based implementation could pass the TTML test suite." ... "interoperability is also important for TTML, which is why there is a fairly comprehensive test suite" - presumably not comprehensive enough if a rough CSS mapping would pass it
00:35
<annevk>
"I find it far from ideal: it isn’t XML" oh god
00:39
<hober>
annevk: indeed
00:42
<annevk>
hmm, IETF is meeting in the Netherlands in July
00:45
<annevk>
Maastricht is somewhat out of the way, but it is certainly not Anaheim
00:46
<othermaciej>
worse than Anaheim for me...
00:48
<roc>
nothing's worse than Anaheim
01:02
<annevk>
so there's certainly ways to simplify the headers
01:03
<annevk>
e.g. we could have (simplified) CORS-Preflight: Method SP [ field-name SP ] +
01:04
<annevk>
and CORS: "credentials"? origin max-age?
01:04
<annevk>
and CORS-Methods and CORS-Headers
01:12
MikeSmith
chuckles at "nothing's worse than Anaheim"
01:27
<annevk>
my idea for http://www.w3.org/2008/webapps/track/issues/90 is either Acces-Control-Expose-Headers or CORS-Expose-Headers in case anyone is wondering
01:28
<annevk>
seemed worthwhile to keep that out of the debate for now
01:29
<annevk>
Tim Bray seems to share the IETF understanding of Web application
03:26
<MikeSmith>
hamaji: if Roland is around at the office today, can you ask him if we are on for lunch at 13:00?
03:27
<MikeSmith>
anne and I are planning to head over there around that time
03:28
<MikeSmith>
hamaji: Roland replied to e-mail anne sent him about it yesterday, just wanted to make sure
03:48
<annevk>
emailed some cors updates to public-webapps
03:48
<annevk>
I wonder if by re-raising dropping withCredentials I can actually get it through this time :)
03:49
<annevk>
it's so super awkward
04:14
<MikeSmith>
Hixie: about http://www.w3.org/Bugs/Public/show_bug.cgi?id=9517
04:14
<MikeSmith>
proposing link/@rel=script
04:15
<annevk>
that's been tried for like a decade
04:15
<annevk>
everyone looking at HTML prolly thinks of that
04:15
<MikeSmith>
I would like to move that back to resolved=wontfix and suggest to dude that if he wants to escalate it, he can ask for it to be raised as a Tracker issue
04:16
<annevk>
but understand it's a bad idea unfortunately takes way more time
04:16
<annevk>
understanding*
04:16
<MikeSmith>
yep
04:17
<MikeSmith>
Hixie: unless you have something more to say about it that you haven't already said
06:59
<Hixie>
man there's been some weird posts to whatwg today
07:11
<nessy>
whatwg? what about public-html? ;)
07:16
<othermaciej>
public-html has been all puppies and sunshine as usual
07:20
<annevk>
except they're not cute
07:22
<nessy>
oohhh
07:43
<Hixie>
nessy: public-html's posts seem par for the course
07:45
<nessy>
well, it's obviously like a cuckoo's egg has been placed in their nest - so it's somewhat a fair reaction - putting the spec past them for input before including in the spec would have been a fairer approach, I guess
07:46
<nessy>
but progress is indeed necessary
07:48
<othermaciej>
it would have been good to at least email an outline of the proposal, even if it is still in the process of being written up, and even if it is going right in the draft
07:48
<othermaciej>
otoh I think people are focusing a bit too much on turf issues and not enough on technical issues
07:48
<othermaciej>
on the third hand, John Foliot filed a bug, which is a good thing to do
07:51
<annevk>
wasn't there an announcement of some sorts?
07:51
<annevk>
and didn't people request Hixie look into this by filing bugs?
07:52
<othermaciej>
I think there was an announcement that he was looking into the area and gathering requirements / use cases / samples
07:52
<annevk>
and the approach has never been to review then commit....
07:53
<othermaciej>
I think this issue has been somewhat fraught even within the accessibility TF
07:53
<annevk>
also, after three years of <video> there hasn't been a concrete proposal; I'm pretty happy Hixie stepped forward and did something
07:53
<Hixie>
i just sent a mail to public-html on this topic
07:53
<othermaciej>
there were some proposals actually, submitted by Silvia, though it's true there is no "official" task force proposal
07:55
<nessy>
annevk: I forwarded two proposals from the a11y TF - it's a little unfair to say there were no concrete proposals - they were incomplete, yes, but they exist
07:56
<nessy>
yeah, othermaciej - the TF is now happy with the JS API, but the markup is still highly disputed, particularly by SMIL people
07:56
<othermaciej>
Hixie: thanks for posting
07:56
<annevk>
nessy, true and it seems most of those proposals has been taken into account
07:56
<othermaciej>
nessy: if the TF likes the way the JS API ended up in the HTML5 draft, then it would be nice to have some acknowledgement of that, so the frame of discussion isn't all about the negative
07:57
<nessy>
yes, I am happy with progress personally
07:57
<nessy>
I don't think it's perfect yet, but I'm sure there is time for reviewing
07:57
<annevk>
nessy, the format part seemed to lack browser backing and maybe also some amount of research (at least the research on the WHATWG wiki came to the conclusion that TTML didn't address all requirements (i.e. <ruby>) and was much too complex
07:58
annevk
is not a fan of "perfect"
07:58
<othermaciej>
I think some people in the TF feel that reviewing a proposal in spec form and pointing out problems / suggesting changes may be in some way worse than starting with a blank slate
07:58
<nessy>
othermaciej: it seems the TF has taken a step back to actually gather requirements and be able to address SMIL issues - I don't think it's a bad thing, but it will certainly delay things
07:58
<othermaciej>
nessy: a requirements document will be extremely useful input
07:59
<nessy>
annevk: "perfect" in the context of HTML ;)
07:59
<othermaciej>
the "perfect" ship has sailed, and HTML was not aboard
07:59
<nessy>
byebye - "perfect" has never ruled the world
07:59
<annevk>
"perfect" is also very personal
08:00
<nessy>
(incidentally, I am having a Friday evening beer, so take my comments with some humour)
08:00
<annevk>
like some people love namespace porn, others find it disgusting
08:00
<Hixie>
HTML is captain of The Mediocre, a leaky but very large cruise ship
08:01
<othermaciej>
mmm, bear
08:01
<othermaciej>
I thought HTML got posted to a new berth on H.M.S. Good Enough
08:01
<annevk>
nessy, I'm two hours away from that
08:01
<annevk>
:)
08:01
<nessy>
hacks rule the world
08:02
<annevk>
there's also "perfect is the enemy of the good"
08:02
<nessy>
I hear twitter is a bad hack only, too
08:02
<nessy>
yeah, tell that to a researcher (speaking as an ex-researcher)
08:02
<Hixie>
the HMS "good enough" or the HMS "ah, screw it, ship this anyway"?
08:02
<annevk>
in the sense that perfect takes care of everything and will never be done (trying to profile TTML) whereas the good (WebSRT) will work in half a year from now
08:03
<othermaciej>
HMS It
08:03
<othermaciej>
Her Majesty's Ship It
08:04
<Hixie>
haha
08:07
<nessy>
lol
08:10
<nessy>
just read that email, Hixie - I wasn't aware of the process, so was good to understand actually - well spoken!
08:13
<MikeSmith>
http://www.lindahenrettadesigns.com/images/020_progress_not_perfection_copy.png
08:14
<MikeSmith>
http://www.lindahenrettadesigns.com/images/029_keep_it_simple_copy.png
08:17
<annevk>
http://www.osnews.com/story/23258/MPEG-LA-owned_Patent_Troll_Sues_Smartphone_Makers is pretty interesting
08:19
<nessy>
yeah - nobody should think they are safe from MPEG-LA! ;)
08:24
<annevk>
markp should post something again on the WHATWG blog
08:24
<annevk>
missing that
08:44
<MikeSmith>
annevk: http://html5.googlecode.com/svn/trunk/spec-splitter/spec-splitter.py
09:07
<ment>
"Nobody expects the Span^H^H^H^Hlawyers from MPEG-LA!"
09:12
<annevk>
http://html5.org/complete/ -- complete.html splitted up
09:13
<annevk>
would be nice if someone could patch up spec-splitter.py for saner splitting though
09:13
<annevk>
it's a bit of a mess currently
09:13
<MikeSmith>
annevk: just treat the filenames as opaque identifiers
09:13
<MikeSmith>
and/or pretend you don't speak English
09:13
<annevk>
you're not helping
09:13
<annevk>
:)
09:15
<annevk>
currently websockets is lumped together with cross-doc messaging and some other communication stuff
09:16
<annevk>
it's better than loading the full spec, but not as great as it would be to have websockets in one section
09:16
<annevk>
s/section/file/
09:16
<jgraham>
annevk++
09:16
<annevk>
(both API and protcol)
09:18
<Hixie>
annevk: if you have a web service i can invoke that returns a tarball or zip file with the files i need to put the file online, i'm happy to integrate it with the script i have and host that multipage complete on the whatwg site -- let me know
09:19
<Hixie>
biggest problem with the spec splitter is it breaks the <dfn> backlinks
09:19
<Hixie>
i use those all the fricking time
09:19
<jgraham>
I really have no idea why Julian is obsessed with the price of devices
09:19
<annevk>
jgraham, I'm not really sure why he expects a different answer this time
09:19
<Hixie>
jgraham: especially given that there'll be open source code that does what he is asking for :-)
09:19
<annevk>
jgraham, it was just an aside, after all
09:19
<Hixie>
jgraham: not to mention that the styling part, which i presume is what he's saying is expensive, is completely optional
09:20
<jgraham>
It seems like a bizzare argument
09:20
<jgraham>
If I wasn't determined to treat responding to any and all timed-text threads as potentially toxic I might call him on it
09:21
<jgraham>
(just because the potential for it becoming a huge timesink seems enormous)
09:22
<annevk>
Hixie, happy to host it, MikeSmith makes sure it updates by invoking some script
09:23
<Hixie>
k
09:23
<Hixie>
(the only reason i can think of to host it on the whatwg site is to make the review tool work)
09:23
<jgraham>
annevk: FWIW I would mildly prefer it on whatwg.org, otherwise I will forget where it is
09:24
<jgraham>
Really I would like whatwg.org/specs/web-apps/complete and whatwg.org/specs/web-apps/complete/multipage
09:24
<jgraham>
or something
09:24
<Hixie>
annevk: if you did want it hosted (also) on the whatwg site, all it would take for me is for you to do a GET to a secret URL, which would then run a script that does a GET on a secret URL on your side which is a tarball that I just expand locally
09:24
<boblet>
Hixie: quick q re: ruby text. Korean “ruby” usage is phonetic pronunciation in hangul, followed by kanji (hanji) in brackets. Coming from a Japanese perspective I figured hangul should be <rt>, but “or other annotations” makes me think the hanji can be <rt>. any comments
09:24
<MikeSmith>
could also just use mod_rewrite to rewrite URLs to make the review tool work
09:25
<jgraham>
So that I can guess the URIs
09:25
<boblet>
MikeSmith: would appreciate your feedback on that one too
09:25
<annevk>
Hixie, so I would need to zip the files and give them back to you?
09:25
<Hixie>
boblet: 90% of those words were greek to me, but in general whatever the small text above the normal in-flow text is, is what you would put in the <rt>
09:26
<boblet>
Hixie: hehe. in Korean’s case the text isn’t above, it’s inline
09:26
<Hixie>
annevk: basically :-)
09:26
<Hixie>
boblet: oh then i wouldn't use <ruby> at all, just use inline text :-)
09:27
<Hixie>
i mean you could use ruby, but it sounds like extra markup for no good reason :-)
09:27
<boblet>
Hixie: wouldn’t that also mean that bopomofo (Chinese) ruby shouldn’t be ruby either?
09:28
<Hixie>
does it get rendered in little letters above or (in vertical text) to the side of the main letters?
09:28
<boblet>
also that line of argument puts ruby in the presentational HTML camp, whereas I perceive it more like abbr
09:28
<zcorpan>
annevk: thanks!
09:29
<Hixie>
boblet: it's not presentational because it does make sense in other media (e.g. speech), but like <h1>, there is a clear expected presentational effect in the visual media
09:30
<boblet>
Hixie: that expected presentation only works in Japanese furigana and Chinese pinyin, but not Chinese bopomofo or Korean
09:31
<boblet>
here’s an image of bopomofo — small characters but vertically to the right (not above) of the kanji: http://oli.jp/img/ruby/bopomofo.png
09:37
<othermaciej>
jgraham: there's certainly a lot of $200 boxes that are powerful enough to browse the web
09:37
<othermaciej>
e.g. Nintendo Wii or iPod touch
09:38
<othermaciej>
there's also the iPhone 3G which can browse the Web for $99
09:38
<Hixie>
boblet: yeah that's another case that makes sense for ruby
09:39
<Hixie>
boblet: i'm just saying there's no point encouraging people to use it for inline formatting, because then they don't benefit from it in any real way
09:39
<boblet>
I understand
09:39
<Hixie>
boblet: it's like how <q> is often not really useful
09:39
<Hixie>
since you can just put quote marks in yourself
09:40
<boblet>
I guess that having the <rt> in parentheses directly after is implicit association
09:41
<boblet>
however, as someone who has battled with understanding squiggles I do see benefit in adding <ruby> even for inline cases
09:41
<boblet>
when you can’t even read the stronger the association the better ;-)
09:46
<kennyluck>
Hey boblet, the "ㄧ" in http://oli.jp/img/ruby/bopomofo.png should be displayed like what's in http://oli-studio.com/temp/bopomofo.png
09:47
<kennyluck>
This is a very weird thing about the bopomofo charter "一"
09:47
<boblet>
aah crap, it snuck back in again
09:47
<kennyluck>
Some UA will render it vertical, some horizontal, it seems.
09:47
<boblet>
yeah
09:48
<boblet>
i need to file some bugs
09:48
<kennyluck>
This is very shitty.
09:49
<annevk>
hmm, someone needs to teach me the zip shellscript stuff
09:50
<MikeSmith>
boblet: I myself have no insight or authoring usage advice to suggest on non-Japanese use cases for ruby annotations
09:50
<annevk>
basically I want to zip the current directory to a file called complete.zip excluding the subversion folder and several other files
09:50
<boblet>
MikeSmith: heh. ok :)
09:50
<annevk>
once I have that I can add a wget to hixie's thing
09:51
<annevk>
for now I'll just keep this as is
09:51
<annevk>
with Mike's update script
09:51
<Hixie>
bbl
09:58
<Lachy>
it's interesting that in the whole thread whinging about WebSRT, there is very little technical feedback explaining why it may be an inappropriate format.
09:58
<Lachy>
It just seems to be more complaints about the process
10:02
<jgraham>
I particularly like the comments that go "SRT doesn't do enough for all usecases so we reject WebSRT"
10:03
<jgraham>
Indicating that there has been no attempt to understand the differences between SRT and WebSRT and the additional use cases this allows it to cover
10:04
<annevk>
I don't really get the reply I get from Steven
10:04
<annevk>
I say it is unclear in the spec why I wouldn't omit alt
10:04
<annevk>
he explains, but then doesn't change the spec to point it out
10:04
<annevk>
was it non-obvious that it was non-obvious in the spec?
10:04
<othermaciej>
file a bug if you want him to change the spec
10:04
<annevk>
that's what he said
10:05
<annevk>
:/
10:05
<othermaciej>
if you think his reasoning is sound, the bug can just say that it's non-obvious
10:05
<annevk>
i don't really care tbh
10:05
<othermaciej>
that's also what Hixie tells me when I ask him to change the spec
10:05
<annevk>
i was just wondering about something
10:05
<othermaciej>
though I guess the non-Hixie drafts don't have inline comments
10:05
<annevk>
hixie would update the spec in reply to an email
10:06
<annevk>
IRC drive-by comments are different
10:06
<annevk>
then you've to get lucky
10:09
<othermaciej>
a public-html email? maybe, maybe not
10:09
<othermaciej>
if I care, I use bugzilla
10:09
<othermaciej>
if I don't care, I don't care
10:17
<annevk>
not my experience
10:26
<annevk>
seems Steven reads the logs in real time
10:26
<annevk>
good times :)
10:27
<annevk>
meanwhile I'm not satisfied with spec-splitter.py
10:27
<annevk>
could it be that it chokes on the newly added <div> elements?
10:27
<annevk>
it doesn't split on all <h2> elements it seems
10:27
<annevk>
Philip` can you debug that?
10:45
<annevk>
blagh
10:45
<annevk>
debugging that script is somewhat frustrating
10:53
<jgraham>
Oh anne left
11:58
<annevk>
jgraham, yeah, not really around
11:59
<annevk>
jgraham, prolly by Sunday I should be somewhat on European time, but not sure if I'm able to patch things up then
11:59
<annevk>
jetlag and general weekend lazyness
11:59
<annevk>
but who n
11:59
<annevk>
knows
11:59
<annevk>
i might get bored :)
12:00
<jgraham>
annevk: Oh well I have forgotten whatever I concluded from reading the script
12:00
<annevk>
next time write it down
12:00
<annevk>
logs are not just for our adversaries
12:00
<jgraham>
It was something like it expects <body>[<div><h2>]*
12:01
<jgraham>
(in some made-up notation)
12:01
<annevk>
as in <h2> nested inside <div>?
12:02
<jgraham>
Oh, that's not quite right
12:02
<annevk>
I played around with just going through the <div> children regardless of class name
12:02
<annevk>
but that seems to always fail
12:02
<annevk>
I should have a somewhat more in dept look at it later
12:18
<gsnedders>
So I killed pulseaudio, it respawned auto-magically, but now picks up no hardware to output sound with :\
12:37
<Lachy>
haha. I like how Julian uses the layer violation argument, while at the same time arguing for the http-equiv attribute in the markup to be left for servers only. Nice irony.
12:43
<Dashiva>
Did anyone ever specify which CMS it is that uses the content-language info for something useful?
12:47
<Lachy>
I don't recall any
12:47
<Lachy>
but CMSs should should store and use that information outside of the HTML templates, if they need it
12:54
<Dashiva>
I agree, but as long as a CMS using it is claimed to exist, it should be possible to specify which one
12:55
<zcorpan>
by extension, it it's not specified which it is, we can assume it doesn't exist
13:05
<zcorpan>
Hixie: i think we should look at existing authoring tools, interpreters, and content
13:05
<zcorpan>
Hixie: unfortunately i don't have the bandwidth to do it myself currently
13:08
<Lachy>
Dashiva, who claimed there was such a CMS in existence?
13:12
<gsnedders>
Roy
13:15
<Dashiva>
This seems to be the closest he ever came to providing details: http://lists.w3.org/Archives/Public/public-html/2010Mar/0286.html
13:20
<hsivonen>
AryehGregor: Does MediaWiki have the capability of varying the HTML it sends out depending on UA string or capability previously sniffed in JavaScript and stored e.g. in a cookie?
13:21
<hsivonen>
AryehGregor: that is, would it be feasible to run Wikipedia's math content through itex2mml and serve math as MathML-in-text/html to new browsers and as images to legacy browsers?
13:30
<Dashiva>
hsivonen: That sounds like a pain for the caching. There already is a user pref for math presentation, though.
13:31
<hsivonen>
Dashiva: oh. I was unaware of the pref
13:37
<Dashiva>
It's a quite confusing pref too, so I guess we can't put much hope in it :)
13:40
<hsivonen>
Dashiva: I get bitmaps with the pref set
13:47
hsivonen
wishes Wikimedia had https working with the same hostname and path as http
13:47
<hsivonen>
or at least Wikipedia
14:27
<Philip`>
annevk: I think it used to split on <h2>s that were direct children of <body>, but then it had to be modified to work with <div class=impl>s and I forget how it works now
14:29
<jgraham>
Philip`: It also looks for <h2>s that are children of <div class=impl>. Which seems like a reasonable way to cover that case...
14:30
<Philip`>
Ah, yes, it looks like it splits on children of body that are either h2 or are div class=impl with an h2 as the first child
14:30
<Philip`>
(so it'll never split a div into two parts)
14:31
<Philip`>
(That would require it to search every element in the document and maintain a stack and clone the current stack when it reaches a splitting point, which would require a bit more effort)
14:32
<Philip`>
(and it takes less effort to ask Hixie to only put one section inside each div)
16:05
<jgraham>
http://www.scribd.com/documents/5/Paper-5
16:38
<foolip>
http://en.wikipedia.org/wiki/Standards_organizations <- I guess this is the page one must be on to be a real standards organization (http://news.cnet.com/8301-30685_3-20004291-264.html)
16:40
<foolip>
"Microsoft prefers standardization to happen earlier in this process so developers don't have to worry about coding different versions of the same pages to accommodate different browsers."
16:41
<foolip>
funny, must be a mistake by the article author
16:41
<Hixie>
i support shipping more often isn't an acceptable alternative to them
16:41
<Hixie>
s/support/suppose/
16:43
<foolip>
perhaps
16:43
<foolip>
if they just want to implement things that other browsers already have and is standardized, that's fine by me
16:44
<foolip>
I just doubt it's true, they'll surely "make shit up" too
17:00
<TabAtkins>
Why is "making the spec smaller" never an appropriate justification when someone wants to keep something useless? It's apparently valid when trying to remove useful things.
17:02
<Hixie>
"making the spec smaller" is never an appropriate justification
17:03
<TabAtkins>
Sure, I know that. I'm just confused that it's only used as a club against useful things, but never brought up as an argument when dealing with useless things like Content-Language.
17:03
<JoePeck>
also it would ruin the market for the inevitable "HTML5 the Good Parts"
17:03
<TabAtkins>
And by confused I mean "I completely understand it, and think that people are inconsistent and bad arguers".
17:04
<Hixie>
TabAtkins: because the people arguing for removing content-language aren't the same people arguing for removing the "useful" things, and different people have different beliefs about what is valid
17:04
<TabAtkins>
Hasn't Julian tried to use "smaller spec" before?
17:04
<Hixie>
JoePeck: actually we drop stuff all the time (e.g. <datagrid>, for a high-profile example), just not for the reason of making the spec smaller :-)
17:05
<Hixie>
TabAtkins: oh, julian.
17:05
<JoePeck>
heh, I know =)
17:05
<Hixie>
TabAtkins: i've given up trying to understand what logic he uses
17:05
<Hixie>
TabAtkins: i gave up roughly when he decided that the ASCII reference was such an important issue it should be escalated
17:06
<Hixie>
TabAtkins: which is so ridiculous as to leave one wondering what can lead to one's priorities being so out of wack
17:06
<theMadness>
The parallels for the "smaller government" outcry are also pretty amusing.
17:07
<TabAtkins>
Smaller government for all the things *you* care about, and larger for all the ones where it could benefit *me*?
17:09
<theMadness>
I left it hanging on purpose. :P
17:09
<TabAtkins>
Hmm. I just realized that I don't specify what happens when you do a linear-gradient(black) (ie, with only one color).
17:09
<TabAtkins>
Or, for that matter, linear-gradient(). How silly of me.
17:09
TabAtkins
goes to check what FF does.
17:10
<TabAtkins>
Syntax error it is, then.
17:52
<Hixie>
i'm amazed at how people in public-html are arguing about whether we should be using CSS or XSL:FO for these subtitles, when it seems pretty obvious to me that either solution is orders of magnitude more complicated than necessary
17:53
<TabAtkins>
I'm just arguing that we shouldn't use both.
17:53
<Hixie>
i mean, sure, we can define a mapping to CSS or XSL:FO or whatever, and it'd be nice to allow CSS to be used in browsers to style the titles in general, but they're just captions, it's not like styling them is critical
17:54
<Hixie>
we can get way beyond the 80/20 line by just having simple rules like "make sure the text is visible", let alone even dealing with positioning or whatnot, which can still be far simpler than CSS or XSL:FO
17:54
Hixie
rants
17:54
<TabAtkins>
But how will I get my text-shadow then? THIS IS CRITICALLY IMPORTANT.
17:57
<dglazkov>
good morning, Whatwg
17:57
<TabAtkins>
Argh, fuck it, I really need to stop responding to random shit Andrew throws out and just focus on what the thread is talking about.
17:58
<AryehGregor>
hsivonen, MathML support is something that would be nice to have for <math>, definitely. The current code to sanitize the LaTeX (strip out stuff like \def to avoid DoS) is written in OCaml, though, and nobody seems really interested in messing with it. There's theoretically some MathML support already, but I have no idea how or if it works.
17:59
<AryehGregor>
You can see the preference to use MathML, but it doesn't seem to work, and I have no idea why.
18:01
<Hixie>
TabAtkins: it should just default to having text shadow
18:02
<dglazkov>
JohnResig: ping
18:04
<AryehGregor>
itex2mml doesn't seem to support actual LaTeX, either, so that sounds like it would be incompatible.
18:04
<AryehGregor>
Unless you do extra preprocessing.
18:04
<AryehGregor>
Although it looks like itex2mml doesn't support anything scary like \def, so it might have bounded running time to begin with and not need sanitization. That would be nice.
18:05
<AryehGregor>
Except we'd have to make sure that texvc's whitelist matches up exactly, which I doubt.
18:06
<AryehGregor>
Practically, we'd probably have to modify texvc to: 1) Check against its own whitelist and reject on failure. 2) Check against itex2mml's whitelist, and if it passes that too, mangle it and pass it through itex2mml. 3) If it doesn't pass itex2mml's whitelist, render to PNG.
18:06
<AryehGregor>
Likely enabled only as a preference, at least on Wikimedia sites, for caching reasons.
18:07
<AryehGregor>
Unless the switch is done with JavaScript.
18:07
<AryehGregor>
Or we can otherwise do graceful fallback.
18:07
<AryehGregor>
My impression is that the graceful fallback for <math>-in-text/html isn't great.
18:07
<AryehGregor>
But fixing up texvc so it will work well is the key thing, that's what will take most of the work.
18:08
<AryehGregor>
There was a GSoC proposal to rewrite texvc in Python so we could actually understand it, but I don't think that was accepted . . .
18:08
<AryehGregor>
Nope. Oh well.
18:09
<AryehGregor>
It'd probably be fairly easy to add a mode that just uses itex2mml and skips texvc unconditionally, but it would be kind of broken.
18:10
<AryehGregor>
Hmm, maybe you could just pass it to both texvc and itex2mml separately, return an error if texvc fails, and use the itex2mml stuff with PNG fallback if both succeed?
18:10
<AryehGregor>
That's a thought.
18:10
<AryehGregor>
Might not be too hard.
18:25
<Dashiva>
People sure are willing to put in tons of effort when it comes to preventing other people from doing work
18:26
<Hixie>
fortunately, they aren't very good at it :-)
18:28
<Dashiva>
Imagine if all the deletionists instead put in some effort on CSSOM...
18:28
<TabAtkins>
They'd just delete it, surely?
21:22
<AryehGregor>
"When the user views a 'my accounts' page in his browser, she sees what information the site is storing about her." https://wiki.mozilla.org/Labs/Weave/Identity/Account_Manager/Spec/Latest
21:22
<AryehGregor>
That's gender-neutrality taken to an extreme, there.
21:31
<TabAtkins>
People just need to accept that singular "they" is valid. Freaking *Shakespeare* used it.
21:36
<AryehGregor>
So does the Bible.
21:36
<AryehGregor>
Which has the even worse problem that all nouns, adjectives, and verbs are gendered, let alone pronouns. (At least the Hebrew and Aramaic parts.)
21:37
<AryehGregor>
It's hopeless to even think about trying "he or she"-type constructions in that setting.
21:37
<TabAtkins>
Wait, are you talking about the bible in hebrew, or in one of the english translations?
21:37
<AryehGregor>
Well, in Hebrew, but I assume the translations follow suit.
21:37
<AryehGregor>
Let me see.
21:40
<AryehGregor>
Deuteronomy 17:5: "Then shalt thou bring forth that man or that woman, which have committed that wicked thing, unto thy gates, even that man or that woman, and shalt stone them with stones, till they die."
21:41
<AryehGregor>
That's KJV. NIV paraphrases, as usual.
21:41
<AryehGregor>
I avoid NIV like the plague for that reason (when I'm using a Christian translation for whatever reason).
21:41
<AryehGregor>
Nice and readable, because they translate it to mean whatever they happen to think it should mean.
21:42
<AryehGregor>
Some really egregious cases there. Of course, the same is somewhat true for any translation, but NIV is way worse than more word-for-word translations like KJV in that regard.
21:48
<AryehGregor>
. . . I'm really curious to know if people have examples of real-world (malicious, not proof-of-concept) MITM attacks on the web.
21:49
<AryehGregor>
Maybe they've been averted by the fact that even incompetent banks/e-commerce sites/whatever tend to use HTTPS.
21:49
<AryehGregor>
So they get the little padlock, or to comply with some industry certification or law or something, I don't know.
21:49
<TabAtkins>
I think that basically *everyone* uses https who needs it.
21:49
<TabAtkins>
Pretty sure it's law, in the case of banks and similar.
21:51
<TabAtkins>
So it might be hard to find actual examples, simply because the ecosystem is so defensive against it in the first place.
21:54
<TabAtkins>
We do have federal wiretapping in the US. That's passive MITM as far as we know, no changes being done to the stream, but it's a definite example of the scenario.
21:55
<TabAtkins>
And in terms of personal attacks, Hixie commits MITM attacks against people using his network on occasion. Just when they're abusing it, and nothing bad, but again, that's an attack scenario.
21:55
<AryehGregor>
I guess.
21:55
<TabAtkins>
Anyone using a wifi connection they don't own is subject to the owner doing things like that.
21:56
<AryehGregor>
Also: http://www.ex-parrot.com/pete/upside-down-ternet.html
21:56
<TabAtkins>
Yeah, very similar.
21:56
<AryehGregor>
None of this is malicious, though, or something web developers have to worry about in practice.
21:56
<AryehGregor>
Most web developers, I mean.
21:56
<TabAtkins>
Authoritarian governments doing wiretapping is something that a web author interested in privacy has to worry about.
21:57
<TabAtkins>
That's not the average author, but still.
21:57
<AryehGregor>
Well, you can't do anything in that case.
21:57
<AryehGregor>
Because one, they can probably forge an SSL certificate.
21:57
<TabAtkins>
Okay, true.
21:57
<AryehGregor>
As long as they have at least one root CA in their country.
21:57
<AryehGregor>
And two, they can still tell what IP address you're connecting to, so unless it's a big shared host or you're using something else like TOR, they can still tell where you're going.
21:58
<AryehGregor>
Which is enough for them to jail you already, if they felt like it.
21:58
<TabAtkins>
Yeah, but that's a separate security issue entirely.
21:58
<TabAtkins>
Encryption can't help with that at all.
21:58
<AryehGregor>
No, you need some form of indirection as well. It's still a MITM attack, though.
21:59
<AryehGregor>
And worth pointing out. If you're trying to hide your activities from the government, and they can get enough info to arrest you or search your computer anyway, then the technology isn't helping.
21:59
<TabAtkins>
What, peeping your IP? Not necessarily. Everyone in the chain knows your IP.
21:59
<AryehGregor>
Well, yes. Everyone in the chain (if by that you mean the path between client and server) is a MITM.
21:59
<AryehGregor>
If they bother.
22:00
<TabAtkins>
Okay, yeah, you're right.
22:00
<AryehGregor>
Anyway, against repressive governments you've pretty much lost from the start. You need social solutions to that, not technical.
22:00
<AryehGregor>
I mean, even if you used TOR, they could throw you in jail or ransack your house or whatever just for that.
22:01
<AryehGregor>
Modern, well-organized governments are essentially invincible to any kind of internal revolt, other than a military coup.
22:01
<TabAtkins>
True.
22:02
<AryehGregor>
I guess you can pressure them in some ways, but technology isn't going to much help you to hide from them. It does help make it harder for them to control information, though.
22:02
<AryehGregor>
. . . anyway. Whatever the case may be, any security scenario where you're trying to defend against a government or comparably powerful organization needs to be treated as an entirely separate category.
22:03
<AryehGregor>
It shouldn't even be brought up in general, if it's just a general web security discussion.
22:03
<TabAtkins>
So we're back to (a) open wifi means that the owner can snoop and alter your traffic easily and (b) anyone in the normal chain of routers between you and the target can do the same.
22:04
<TabAtkins>
But right now, SSL's security against MITM and general ubiquity in cases where MITM would be a profitable exploit means that actual example of MITM are necessarily going to be few and far between.
22:04
<AryehGregor>
Yep. I'd still like to see one real-world (malicious, non-government) case, though. :)
22:04
<TabAtkins>
I'd have to poke around, and I don't feel like doing that.
22:06
<AryehGregor>
"Every so often I receive extremely irate e-mails from people claiming that my Kittenwar site is playing host to some kind of nefarious virus preventing them from accessing the web, accusing me of practising all sorts of dark arts - to which I politely respond that I'm terribly sorry, but this only usually happens to people who are using someone else's wireless connection, and pointing them in the direction of your site. This has happened doz
22:06
<AryehGregor>
ens of times over the last few years, and you know what? None of them have ever got back to me after I point this out."
22:06
<AryehGregor>
Hahaha.
23:22
AryehGregor
has gotten bored of responding to Juuso Hukkanen
23:34
<AryehGregor>
People who don't know what they're talking about I don't mind, but when they're hopelessly vague, unreasonably prolix, and smug at the same time, I have a limited attention span.
23:39
<TabAtkins>
Yeah, that's why I kept my emails to him short so far. That's more than he deserves.
23:41
<AryehGregor>
If he seemed willing to accept factual corrections, I'd be happy to give them, but we're just "complaining" about his awesome idea.