meeting: Security and Privacy task force
chair: Oliver
agenda: https://lists.w3.org/Archives/Public/public-wot-ig/2015Sep/0001.html
scribenick: dsr
Topic: Feedback on kick-starting the discussion of "Things Discovery
present: Oliver, Dave, Arne, Carsten, Claes, Dan, Yingying
Oliver summarises where we are in respect to authorisation for discovery, see https://www.w3.org/WoT/IG/wiki/Things_Discovery_Authorization
We have a draft problem statement
Oliver intoduces the section on the state of the art
… and the IT security perspective
We need to elaborate with further details
Oliver invites comments from the people on the call
The most important point it is that we can easily formulate the problem statement, but the rest will be harder.
Carsten: the act of discovery discloses privacy related info, and hence can require authorisation
We have discovery involving other parties, and also cold discovery …
Oliver: my suggestion is to invite volunteers to assist with rewriting/extending the wiki text
Carsten volunteers to help
Oliver: the problem statement should be short
present+Darshak Thakore
Oliver: I would suggest that the discovery task force take the lead on this
Oliver asks if Carsten can make his input on the wiki within one week
Carsten: we could also help with filling in the security perspective based on our experience in the IETF
Topic: Status and next steps for SP
s/SP/SP Landscape/
see: https://www.w3.org/WoT/IG/wiki/Design-Time_Security%26Privacy_Means#Mechanisms
Please take a look and provide any feedback you may have
I did some restructuring
The old version was perhaps too bottom up. We now start with the main findings and then add details by way of explanations.
The text in the table is in some cases a little long
… or is missing
I would like you to review the mechanisms and to see if there are missing technologies that should be added here. Right now we have around 17 mechanisms
s/mechanisms/technologies/
Oliver asks for feedback within the next 2 weeks if at all possible.
Has anybody had a chance to look at this so far? [no]
He distinguishes classic, new and future technologies on the basis of existing standards and the time they were introduced
s/time/date/
We have less clear understanding of new technologies, so need to get back to the authors to clarify things as needed
My aim is to have a full review in two weeks or so
Oliver asks for comments from people on the call [none]
Topic: Status and next steps for SP Requirements
See https://www.w3.org/WoT/IG/wiki/Security%26Privacy_Requirements_Catalogue
I am in touch with the other task forces to seek input on use cases with security requirements.
Oliver: my aim is to finalise our report at the next face to face (in Sapporo)
Who plans to attend?
Carsten: yes
Dave: yes
Dave reminds people to register for TPAC see http://www.w3.org/2015/10/TPAC/
Oliver: any other business for today? [none]