I think the letter is fine, except that in this case I don't think we should mention the membership <br><br>In this context for the non-members it can be seen as a OWASP is threatening them (and it almost implies that if they become members it will be fine)
<br><br>No including this information, also simplifies the process since we will have one unique letter for everybody (whose template can even be posted on the WIKI)<br><br>Dinis<br><br><br><br><div><span class="gmail_quote">
On 1/31/07, <b class="gmail_sendername">Jeff Williams</b> <<a href="mailto:jeff.williams@owasp.org">jeff.williams@owasp.org</a>> wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">











<div link="blue" vlink="blue" lang="EN-US">

<div>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">Seems reasonable to me.  How does this look for a
standard letter to send to people who misuse our brandů  Obviously
we'll have to change the last paragraph for folks who are already
members.  Not that membership is permission to abuse the brand.</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">What do you thinků</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">Subject: OWASP Top Ten reference</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">Hi,</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">We've been notified that your company is referencing
the OWASP Top Ten [ on your website | in your press release | in your marketing
material ] here [ URL ].  You may not know that OWASP has a set of established
brand usage rules that govern the use of the OWASP name and logo.</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"><a href="http://www.owasp.org/index.php/OWASP_brand_usage_rules" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.owasp.org/index.php/OWASP_brand_usage_rules
</a></span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">Could you provide details of how your [ product | service ]
matches up with the Top Ten?  In particular, can you confirm that you
provide complete [ detection | protection ] for all the possible
vulnerabilities covered by each item in the Top Ten?</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">Going forward, we'd like you to reference the OWASP
Top Ten 2007 Update, which is more focused and is likely to be easier for you
to address. The first release candidate has been posted to our website, and is
likely to become final in early Spring.</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"><a href="http://www.owasp.org/index.php/Top_10_2007" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.owasp.org/index.php/Top_10_2007
</a>.
</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">Finally, I'd like you to consider becoming an OWASP
member and supporting our efforts.  Membership is a great way to help
promote application security and gain visibility for your company.</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"><a href="http://www.owasp.org/index.php/Membership" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.owasp.org/index.php/Membership
</a></span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">Please don't hesitate to contact me to discuss any of
the above.  Thanks,</span></font></p>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;"> </span></font></p>

<div>

<div>

<p><font face="Arial" size="2"><span style="font-size: 10pt; font-family: Arial;">--Jeff</span></font></p>

</div>

</div>

<div>

<p><font face="Times New Roman" size="3"><span style="font-size: 12pt;"> </span></font></p>

<p><font face="Times New Roman" size="3"><span style="font-size: 12pt;"> </span></font></p>

<div style="text-align: center;" align="center"><font face="Times New Roman" size="3"><span style="font-size: 12pt;">

<hr align="center" size="3" width="100%">

</span></font></div>

<p><b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma; font-weight: bold;">From:</span></font></b><font face="Tahoma" size="2"><span style="font-size: 10pt; font-family: Tahoma;"> Andrew van der
Stock [mailto:<a href="mailto:vanderaj@owasp.org" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">vanderaj@owasp.org</a>] <span class="q"><br>
<b><span style="font-weight: bold;">Sent:</span></b> Wednesday, January 31, 2007
10:27 AM<br>
<b><span style="font-weight: bold;">To:</span></b> Jeff Williams; OWASP Board<br>
<b><span style="font-weight: bold;">Subject:</span></b> Re: [Owasp-board] Ounce
Labs vs. OWASP Top Ten</span></span></font></p>

</div>

<p><font face="Times New Roman" size="3"><span style="font-size: 12pt;"> </span></font></p><div><span class="e" id="q_110790a728b09b30_3">

<p style="margin-bottom: 12pt;"><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;">Could we ask them nicely, to:</span></font></p>

<ol start="1" type="1">
 <li><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;">describe how they comply with the Top 10 2004
     in some detail </span></font></li>
 <li><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;">Ask them to consider updating it to the T10
     2007 which is far more detectable </span></font></li>
 <li><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;">Ask them to be a corporate member?</span></font></li>
</ol>

<p style="margin-bottom: 12pt;"><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;"><br>
Thanks,<br>
Andrew<br>
<br>
<br>
On 1/31/07 10:20 AM, "Jeff Williams"
<<a href="mailto:jeff.williams@aspectsecurity.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">jeff.williams@aspectsecurity.com</a>> wrote:</span></font></p>

<p style="margin-bottom: 12pt;"><font face="Arial" size="1"><span style="font-size: 8pt; font-family: Arial;"><a href="http://www.marketwatch.com/news/story/story.aspx?guid=698DA76292D746EA96DA1822BA941E37&siteid=mktw&dist=nbk" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://www.marketwatch.com/news/story/story.aspx?guid=698DA76292D746EA96DA1822BA941E37&siteid=mktw&dist=nbk</a><br>
 <br>
--Jeff<br>
</span></font><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;"><br>
</span></font><font size="2"><span style="font-size: 9.5pt;"><br>
</span></font><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;"><br>
</span></font><font face="Arial" size="1"><span style="font-size: 8pt; font-family: Arial;">Jeff Williams, CEO<br>
</span></font><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;"><br>
</span></font><font face="Arial" size="1"><span style="font-size: 8pt; font-family: Arial;">Aspect Security <a href="http://www.aspectsecurity.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
<http://www.aspectsecurity.com/></a>
<br>
</span></font><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;"><br>
</span></font><font face="Arial" size="1"><span style="font-size: 8pt; font-family: Arial;">work: 410-707-1487<br>
</span></font><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;"><br>
</span></font><font face="Arial" size="1"><span style="font-size: 8pt; font-family: Arial;">main: 301-604-4882<br>
</span></font><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;"><br>
<br>
</span></font></p>

<div style="text-align: center;" align="center"><font face="Verdana" size="1"><span style="font-size: 7pt; font-family: Verdana;">

<hr align="center" size="3" width="100%">

</span></font></div>

</span></div><p><font face="Courier New" size="1"><span style="font-size: 6pt;"><div><span class="e" id="q_110790a728b09b30_5">_______________________________________________<br>
Owasp-board mailing list<br>
<a href="mailto:Owasp-board@lists.owasp.org" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">Owasp-board@lists.owasp.org</a><br></span></div>
<a href="http://lists.owasp.org/mailman/listinfo/owasp-board" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://lists.owasp.org/mailman/listinfo/owasp-board</a></span></font></p>

<p><font face="Times New Roman" size="3"><span style="font-size: 12pt;"> </span></font></p>

</div>

</div>


<br>_______________________________________________<br>Owasp-board mailing list<br><a onclick="return top.js.OpenExtLink(window,event,this)" href="mailto:Owasp-board@lists.owasp.org">Owasp-board@lists.owasp.org</a><br><a onclick="return top.js.OpenExtLink(window,event,this)" href="http://lists.owasp.org/mailman/listinfo/owasp-board" target="_blank">
http://lists.owasp.org/mailman/listinfo/owasp-board</a><br><br></blockquote></div><br><br clear="all"><br>-- <br>Dinis Cruz<br>Chief OWASP Evangelist, Are you a member yet?<br><a href="http://www.owasp.org">http://www.owasp.org
</a>