12:02:49 RRSAgent has joined #wot-sec 12:02:54 logging to https://www.w3.org/2023/05/22-wot-sec-irc 12:03:29 present+ Kaz_Ashimura, Michael_McCool, Jiye_Park, Luca_Barbato, Tomoaki_Mizushima 12:03:49 agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#22_May_2023 12:07:57 scribenick: luca_barbato 12:08:12 topic: Previous Minutes 12:09:16 -> https://www.w3.org/2023/05/15-wot-sec-minutes.html May-15 12:09:25 mm: Consensus on publishing? 12:09:29 12:11:00 topic: Architecture PR drafts 12:11:09 https://github.com/w3c/wot-architecture/pull/909 12:11:17 https://github.com/w3c/wot-architecture/pull/910 12:11:24 https://github.com/w3c/wot-architecture/pull/911 12:11:31 https://github.com/w3c/wot-architecture/pull/912 12:11:36 mm: We merged all those above 12:11:38 https://github.com/w3c/wot-architecture/pull/913 12:11:56 s/mm: We merged all those above// 12:12:30 mm: We merged all those, but we can review and make sure nothing is left over 12:13:43 mm: I clarified the statement about guest network to match reality 12:14:25 ... segmented network is now used instead of the wrongly stated guest network 12:14:51 s|https://github.com/w3c/wot-architecture/pull/909|-> https://github.com/w3c/wot-architecture/pull/909 wot-architecture PR 909 - Resolve arch-security-consideration-use-psk| 12:15:00 ... and I clarified authorization using access control instead 12:15:08 q+ 12:15:11 mm: No problem with the rewording? 12:15:15 12:16:41 i|909|subtopic: PRs already discussed and merged during the previous Architecture call| 12:16:59 ack k 12:17:06 kaz: We are reviewing the architecture pull request that are already merged 12:17:28 s|https://github.com/w3c/wot-architecture/pull/910|-> https://github.com/w3c/wot-architecture/pull/910 wot-architecture PR 910 - Resolve arch-security-consideration-dtls-1-3| 12:17:33 mm: They already got discussed and approved in architecture, but I want to have the security experts to doublecheck 12:18:01 s/already merged/already merged. right?/ 12:19:09 s|https://github.com/w3c/wot-architecture/pull/911|-> https://github.com/w3c/wot-architecture/pull/911 wot-architecture PR 911 - Resolve arch-security-consideration-hal-refuse-unsafe| 12:19:23 mm: Please speak up if you see a problem with the PR as I recap them 12:19:40 s|https://github.com/w3c/wot-architecture/pull/912|-> https://github.com/w3c/wot-architecture/pull/912 wot-architecture PR 912 - Revise native to low-level hardware| 12:20:15 s|https://github.com/w3c/wot-architecture/pull/913|-> https://github.com/w3c/wot-architecture/pull/913 wot-architecture PR 913 - Change IoT ecosystem to IoT Platform| 12:20:21 rrsagent, make log public 12:20:28 rrsagent, draft minutes 12:20:30 I have made the request to generate https://www.w3.org/2023/05/22-wot-sec-minutes.html kaz 12:20:45 Jiye_ has joined #wot-sec 12:21:25 Jiye__ has joined #wot-sec 12:21:31 mm: 911 and 912 impact the same section so it is better to look at the final result 12:22:07 q+ 12:22:44 mm: A `native` specifier is still left over 12:25:58 lb: while at it the statement about why the abstration layer is useful should be moved up 12:27:24 mm: I'll prepare a pr to replace `native` with `low-level` to be consistent with the rest of the document 12:30:37 q+ 12:30:42 mm: The flow of statements would be better as is 12:30:49 q- 12:32:12 ack k 12:32:23 kaz: The current order is fine 12:32:51 mm: Better to fix only the naming 12:33:26 kaz: We can consider adding the defintion of `hardware abstraction layer` later 12:34:08 s/later/for the next version spec/ 12:34:19 topic: Thing Description pending PR 12:34:37 mm: A number of PR not yet merged 12:35:27 ... they mainly are about moving from SHOULD (assertion) to should (not assertion) 12:35:30 https://github.com/w3c/wot-thing-description/pull/1826 12:35:37 https://github.com/w3c/wot-thing-description/pull/1827 12:35:43 https://github.com/w3c/wot-thing-description/pull/1828 12:37:15 subtopic: PR 1828 12:37:39 s|https://github.com/w3c/wot-thing-description/pull/1826|-> https://github.com/w3c/wot-thing-description/pull/1826 wot-thing-description PR 1826 - Resolve privacy-immutable-id-as-property| 12:37:41 mm: All the references to the device flow are removed 12:38:19 s|https://github.com/w3c/wot-thing-description/pull/1827|-> https://github.com/w3c/wot-thing-description/pull/1827 wot-thing-description PR 1827 - Resolve security-context-secure-fetch| 12:38:45 mm: People can provide feedback until the PR is discussed and merged in the TD call this week. 12:38:56 s|https://github.com/w3c/wot-thing-description/pull/1828|-> https://github.com/w3c/wot-thing-description/pull/1828 wot-thing-description PR 1828 - Resolve td-security-oauth2-device-flow| 12:39:03 topic: Discovery Pending PRs 12:39:15 i|All the refe|-> https://github.com/w3c/wot-thing-description/pull/1828 wot-thing-description PR 1828 - Resolve td-security-oauth2-device-flow| 12:39:47 mm: Lots of PR, many cover multiple concerns by interest 12:39:58 https://github.com/w3c/wot-discovery/pull/485 12:40:00 subtopic: PR 485 12:40:36 mm: Not enough implementations using Oauth2 for bootstrapping 12:41:24 ... The `client` Oauth2 is supported 12:42:25 s|https://github.com/w3c/wot-discovery/pull/485|| 12:42:54 mm: We can discuss futher this in the Discovery call 12:43:02 i|Not enough|-> https://github.com/w3c/wot-discovery/pull/485 wot-discovery PR 485 - Resolve exploration-secboot-oauth2-flows| 12:43:13 subtopic: PR 486 12:43:42 mm: This PR demotes assertion terms to not assertion (e.g. SHOULD -> should, MAY -> may) 12:44:00 https://github.com/w3c/wot-discovery/pull/487 12:44:18 subtopic: PR 487 12:44:45 mm: This also demotes assertions as well. 12:47:10 subtopic: PR 402 12:47:12 i|This PR d|-> https://github.com/w3c/wot-discovery/pull/486 wot-discovery PR 486 - Resolve security assertions| 12:47:37 DID is related to security, but requires additional polishing and a diagram 12:47:59 subtopic: PR 185 12:48:05 i|This also demo|-> https://github.com/w3c/wot-discovery/pull/487 wot-discovery PR 487 - Resolve privacy assertions| 12:48:06 q+ 12:48:25 This has to be deferred, but it is interesting 12:48:38 s/This has to be deferred, but it is interesting/mm: This has to be deferred, but it is interesting/ 12:49:09 kaz: We should have another discussion with all the WG participants 12:50:51 mm: I prefer splitting by topic and have the WG have a last say 12:51:50 mm: We would have a scheduling problem to leave 2 weeks for review 12:57:46 lb: This should belong to Profile and not Discovery 12:57:52 kaz: Do you think having a 2-hour Discovery call today would be able to finalize the difficult situation? If so, I think that meeting would be kind of similar to my proposed dedicated meeting to finalize the updates around the features at-risk removal./ 12:58:05 s|removal./|removal.| 12:59:05 s|We should have another discussion with all the WG participants|Given the discussion so far during this call, I've started to feel we should have another dedicated meeting with all the WG participants to finalize the removal of features at-risk.| 12:59:11 rrsagent, make log public 12:59:17 rrsagent, draft minutes 12:59:18 I have made the request to generate https://www.w3.org/2023/05/22-wot-sec-minutes.html kaz 13:00:16 i/Do you/scribenick: kaz/ 13:00:26 scribenick: luca_barbato 13:00:49 s/lb: This should belong to Profile and not Discovery// 13:00:49 lb: This should belong to Profile and not Discovery 13:00:55 [adjourned] 13:01:21 rrsagent, draft minutes 13:01:22 I have made the request to generate https://www.w3.org/2023/05/22-wot-sec-minutes.html kaz 13:01:34 chair: McCool 13:01:36 rrsagent, draft minutes 13:01:37 I have made the request to generate https://www.w3.org/2023/05/22-wot-sec-minutes.html kaz 13:02:13 meeting: WoT Security 13:02:14 rrsagent, draft minutes 13:02:16 I have made the request to generate https://www.w3.org/2023/05/22-wot-sec-minutes.html kaz 13:03:35 i|DID is related to|-> https://github.com/w3c/wot-discovery/issues/402 wot-discovery PR 402 - Register DID service names| 13:04:25 s|DID is related to|mm: DID is related to| 13:05:18 i|This has to be def|-> https://github.com/w3c/wot-discovery/issues/185 wot-discovery Issue 185 - OAuth2 and SSE Notificiations| 13:05:26 s/PR 185/Issue 185/ 13:05:30 rrsagent, draft minutes 13:05:31 I have made the request to generate https://www.w3.org/2023/05/22-wot-sec-minutes.html kaz 13:06:51 i/This should be/scribenick: kaz/ 13:06:53 rrsagent, draft minutes 13:06:54 I have made the request to generate https://www.w3.org/2023/05/22-wot-sec-minutes.html kaz 13:59:46 Mizushima has left #wot-sec 15:05:58 Zakim has left #wot-sec