15:59:42 RRSAgent has joined #wpwg-spc 15:59:42 logging to https://www.w3.org/2021/08/23-wpwg-spc-irc 15:59:47 Meeting: SPC Task Force 16:00:02 Agenda: https://lists.w3.org/Archives/Public/public-payments-wg/2021Aug/0032.html 16:00:03 Chair: Ian 16:00:05 Scribe: Ian 16:00:24 present+ 16:00:48 present+ 16:01:15 present+ Stephen_McGruer 16:01:18 present+ Anne_Pouillard 16:01:24 present+ Susan_Pandy 16:01:31 present+ Adrian_Hope-Bailie 16:01:54 Anne has joined #wpwg-spc 16:02:08 agenda+ Issue 101 16:02:13 agenda+ Issue 84 16:02:39 agenda+ Issue 109 16:03:19 present+ Doug_Fisher 16:03:26 present+ Michel_Weksler 16:03:37 zakim, take up item 1 16:03:37 agendum 1 -- Issue 101 -- taken up [from Ian] 16:03:44 https://github.com/w3c/secure-payment-confirmation/issues/101 16:03:49 Proposal: support data URIs for card art icons 16:04:45 Stephen: To simplify Account Provider support, can use data URI for icon instead of running a web server. 16:05:03 ...so proposal is that we hash the data URL. 16:05:22 ...works for both https and data URLs 16:06:36 present+ Praveena_Subrahmany 16:07:36 AdrianHB: What if merchant is given 100 logos by the RP? (Even if out of scope for SPC) 16:07:59 Stephen: Technically, an RP could keep a set of hashes around. 16:08:16 AdrianHB: Anything needed re: hashing? 16:08:21 ..specifics about (complicated) hashing? 16:08:51 mweksler has joined #wpwg-spc 16:10:17 AdrianHB: The browser needs to do the hash since it needs to be sure the hash corresponds to the image 16:10:55 ...can we name the hash method? 16:11:04 ...look at CSR 16:11:31 Stephen: Hash collision attack is possibly but unlikely 16:11:59 s/CSR/CSP 16:12:54 Doug: A downside of this approach: images change over time; hash of image at time of authentication may not be same at validation time 16:13:05 ...and images are cached by merchants 16:14:47 ...one mitigation strategy is for the RP to provide fresh images (e.g., via ACS) 16:15:46 Stephen: I think data URL is a reasonable compromise -- the RP passes the data URL to the merchant 16:17:29 ...we have advised to the 3DS WG that all the information required for the SPC call is passed at the time of the request 16:17:30 q? 16:18:02 Doug: Are we also talking about display of the issuer logo? 16:18:28 Stephen: At the moment, no. Just one icon for now ('for the instrument') 16:18:33 q+ 16:18:45 Stephen: It's reasonable to look into another icon 16:20:34 Ian: Is it important to tell the user to whom they are authenticating (the RP)? 16:20:48 Doug: Our UX experiments show that it's important to show the user to whom they are authenticating. 16:20:56 Ian: This may also be true in open banking context 16:21:31 Doug: When SPC fails, we'd also like to have some continuity (in UI) to fallback authentication 16:21:40 ...so I think having extra UI about RP would be important to the consumer 16:23:14 AdrianHB: I think there's no harm to show origin of RP. We should allow the RP to say what icon to show (for them) 16:23:41 ...they may choose through their own experimentation that showing a network logo is effective, or a combo logo, or whatever 16:24:14 ...this is a mechanism for the RP to show the user some graphical clue about what the user is about to do, and a hash of the bytes would be part of the assertion. 16:24:58 ...maybe a single logo suffices if the RP gets to say what it is 16:27:02 topic: Issue 84 16:27:03 https://github.com/w3c/secure-payment-confirmation/issues/84 16:27:40 Ian: Can we close this one with "No UX in v1" 16:28:18 ACTION: Stephen to close issue 84 with explanation about v1 status and reopen later if needed. 16:28:29 Topic: FPWD 16:29:21 Ian: Ready? 16:29:31 Stephen: Coming soon - tx confirmation requirements 16:30:28 Ian: I will aim for 25 August 16:30:33 Topic: next call 16:31:08 30 August 16:31:11 No meeting 6 September 16:31:15 I have made the request to generate https://www.w3.org/2021/08/23-wpwg-spc-minutes.html Ian 16:31:56 Topic: Any origin trial changes? 16:32:24 Stephen: See https://lists.w3.org/Archives/Public/public-payments-wg/2021Aug/0027.html 16:32:45 Ian: Note in particular: 16:32:51 * 0 credential match UX 16:32:59 * No enrollment UX 16:33:15 RRSAGENT, make minutes 16:33:15 I have made the request to generate https://www.w3.org/2021/08/23-wpwg-spc-minutes.html Ian 16:33:20 RRSAGENT, set logs public 16:33:28 RRSAGENT, set logs public 16:38:36 rrsagent, bye 16:38:36 I see 1 open action item saved in https://www.w3.org/2021/08/23-wpwg-spc-actions.rdf : 16:38:36 ACTION: Stephen to close issue 84 with explanation about v1 status and reopen later if needed. [1] 16:38:36 recorded in https://www.w3.org/2021/08/23-wpwg-spc-irc#T16-28-18