12:01:09 RRSAgent has joined #wot-sec 12:01:09 logging to https://www.w3.org/2019/09/02-wot-sec-irc 12:01:13 Meeting: WoT Security 12:01:29 present+ Kaz_Ashimura, Elena_Reshetova, Michael_McCool 12:07:41 McCool has joined #wot-sec 12:08:33 scribenick: kaz 12:09:09 Agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Agenda 12:09:17 topic: Review minutes 12:09:33 -> https://www.w3.org/2019/08/26-wot-sec-minutes.html Aug-26 minutes 12:09:42 mm: don't see any problems 12:09:51 ... objections to accept the minutes? 12:09:54 (no objections) 12:09:57 mm: accepted 12:10:16 topic: Rescheduling the security call 12:10:29 -> https://doodle.com/poll/uygq7wtn75syw8h2 Doodle 12:10:54 mm: Taki can't make Monday 12:11:11 ... any preference on the slots on Monday? 12:11:16 er: no preference 12:11:31 mm: prefer the later time 12:11:33 kaz: me too 12:11:48 mm: so let's go with 7am JST 12:12:30 action: kaz to allocate a new webex and distribute it for the next week 12:12:38 kaz: will do 12:12:58 mm: after talking with Taki, we might be going to change the slot again 12:13:05 (Zoltan joins) 12:13:17 mm: Zoltan, we were talking about the new slot for the Security call 12:13:22 ... (explains the situation) 12:13:58 er: it's 1pm in Finland 12:14:02 zk: ok 12:14:37 ... fine by me though might be a bit late 12:15:17 topic: WG Charter draft 12:16:01 -> https://github.com/w3c/wot/pull/856 PR 856 12:16:02 https://github.com/w3c/wot/blob/master/charters/wot-wg-charter-draft-2019.html 12:16:12 mm: the initial PR (PR 856) has been merged 12:17:16 http://w3c.github.io/wot/charters/wot-wg-charter-draft-2019.html 12:17:44 mm: rendered version above 12:17:50 ... as far as security goes 12:18:04 ... topics on security within "2. Scope" 12:18:24 ... also Interoperability Profiles 12:18:29 ... Discovery 12:18:40 ... need to work with the Privacy group 12:18:55 ... security aspects for Implementation View Spec as well 12:19:42 ... 2.6 Discovery 12:20:02 ... we have to define deliverables 12:20:19 ... possibly break out into 2 pieces 12:20:42 ... introduction and exploration 12:21:12 ... peer-to-peer discovery could be supported as a special case 12:21:24 ... have to coordinate with IETF, etc. 12:21:35 ... need more general context here 12:21:43 ... 2.7 Identity Management 12:22:04 ... Kaz mentioned there is a proposed WG named the Decentralized ID WG 12:22:10 ... should collaborate with them 12:22:37 ... kind of like ID management lifecycle 12:22:56 ... e.g., please notify me when the ID management changes 12:23:08 ... device with right access to be handled 12:23:33 ... we have a deliverable down here ("3. Deliverables") 12:23:51 ... we need to create repos for those deliverables 12:24:01 ... would like to start soon 12:24:10 ... Michael Lagally is generating draft as well 12:24:43 ... any comments? 12:24:51 zk: discovery for WoT? 12:25:04 ... do we want to define ourselves? 12:25:05 mm: good point 12:25:15 ... have predescribed script 12:25:32 ... in fact we're doing how to distribute things 12:25:44 ... because existing devices don't distribute TDs 12:26:04 zk: distributing script as well? 12:26:04 mm: maybe 12:26:10 s/maybe/may be/ 12:26:20 zk: some king of manifest of something 12:26:30 ... some kind of package 12:26:32 s/king/kind/ 12:26:48 mm: bunch of things that are listed as "Notes" 12:27:15 ... normative deliverables are extracted from the powerpoint we discussed in Munich 12:27:40 zk: was there any deliverable which can be included as Note? 12:27:44 mm: hold on... 12:28:17 ... (shares the powerpoint slide from Munich) 12:28:44 ... other things used to on the REC track 12:29:05 ... essentially deployment model and packaging 12:29:13 ... WG Charter can be changed later 12:29:23 ... what we should do is 12:29:45 ... if you think deployment/packaging mechanism for Scripting would be useful, you can create a PR for that proposal 12:29:56 ... the current list is generated from the powerpoint in Munich 12:30:04 zk: ok 12:30:08 ... some provisions to associate things 12:30:23 ... should be contained to Scripting distribution mechanism 12:30:33 mm: 2 kinds of dependency 12:30:42 ... MPM kind of packaging 12:30:48 ... and function 12:31:36 ... query mechanism and installation mechanism 12:31:53 zk: we don't have to re-invent generic distribution mechanism 12:32:09 mm: packaging of script 12:32:14 ... there is dependency 12:32:18 ... 2 parts of manifest 12:32:26 s/MPM/NPM/ 12:32:34 ... very interesting 12:33:04 zk: let's say I discover things and would know about the capability of scripts 12:33:09 ... up to the clients 12:33:52 mm: please review this draft Charter 12:34:04 ... and also proposals from Michael Lagally 12:34:36 -> https://w3c.github.io/wot-profile/ wot-profile proposal 12:35:00 (Elena leaves) 12:35:38 mm: what is the right context to handle the context? 12:35:47 ... have been talking about the orchestrator 12:36:06 ... e.g., Panasonic, etc., use node-red 12:36:41 q+ 12:38:04 mm: we could add another deliverable for management script 12:38:16 ... need context for interoperability 12:38:42 ... just like profile, we need draft text which describes the context and the basic architecture 12:38:47 ... would be useful to do 12:39:37 ... personally started to think Scripting API could be a Note by the IG 12:39:54 ... IG should be incubating the requirements 12:40:24 zk: it's specific to node-wot and typescript 12:40:36 mm: we could add management API 12:40:46 ... with packaging capability 12:41:05 zk: JS is the language supported by Web browsers 12:41:25 ... that might be one way to go for something like Web Assembly 12:41:46 mm: what to be contained for packaging? 12:42:06 ... those things could be interesting 12:42:23 zk: right now we have JS runtime 12:42:35 ... there are some issues to tackle 12:42:46 ... it's something would make sense 12:42:56 ... but not directly related to WoT 12:43:32 mm: if we go for more general mechanism for packaging 12:44:08 ... need a draft text to be included in the draft Charter 12:44:27 ... need same thing for packaging and/or management API 12:45:40 kaz: it sounds like object-oriented programming 12:45:57 ... how to combine the TD model and Scripting API as a possible method for the data model 12:46:24 mm: would create an issue about this point 12:51:20 https://github.com/w3c/wot/issues/861 12:52:39 mm: WG Charter issue above 12:52:56 ... also it would be nice to have a specific repo for the wot-discovery discussion 12:53:17 ... will generate a draft first 12:53:26 ... and let's have discussion during the main call 12:54:45 zk: regarding the above Issue 861 12:55:11 ... we need use cases to motivate it 12:55:14 mm: ok 12:55:19 ... (adds comment on that point) 12:55:31 ... why don't you add your comments to this thread? 12:55:32 zk: ok 12:56:00 [adjourned] 12:56:03 rrsagent, make log public 12:56:13 rrsagent, draft minutes 12:56:13 I have made the request to generate https://www.w3.org/2019/09/02-wot-sec-minutes.html kaz 16:09:26 zkis has joined #wot-sec 17:23:49 zkis has joined #wot-sec