12:59:08 present+ Kaz_Ashimura, Michael_McCool
13:00:50 luca_barbato has joined #wot-sec
13:01:17 McCool has joined #wot-sec
13:01:48 present+ Luca_Barbato
13:03:58 Mizushima has joined #wot-sec
13:04:29 agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#4_September_2023
13:05:29 present+ Tomoaki_Mizushima
13:06:24 scribenick: luca_barbato
13:06:31 topic: Minutes
13:07:04 -> https://www.w3.org/2023/08/07-wot-sec-minutes.html Aug-7
13:07:33 mm: We agreed to review the minutes offline, but let's go over it to recap what we left last month
13:08:17 mm:
13:08:22 topic: PRs
13:08:38 mm: 4 PR pending
13:08:54 subtopic: PR 226
13:08:56 -> https://github.com/w3c/wot-security/pull/226 PR 226 - Migrate to new ReSpec profile
13:09:51 It updates the respec version and address its lints
13:10:11 mm: It updates the respec version and address its lints
13:10:29 subtopic: PR 225
13:10:31 -> https://github.com/w3c/wot-security/pull/225 PR 225 - Add DDoS Threats
13:12:14 mm: It add a section about DDoS next to the current DoS section
13:12:47 mm: I added the definition and then added few examples
13:14:07 mm: I'd like to have more people to review it
13:14:20 subtopic: PR 224
13:14:24 -> https://github.com/w3c/wot-security/pull/224 PR 224 - Add anchors to threats
13:16:34 mm: I would not merge this pr since it adds additional overhead and might desync
13:18:40 lb: I agree, might be good to ask the respec developers to improve the usability
13:19:36 mm:
13:20:30 topic: TPAC Agenda
13:21:36 -> https://www.w3.org/WoT/IG/wiki/Main_WoT_WebConf/2023_WoT_TPAC_Agenda TPAC WoT agenda wiki
13:22:47 mm: My intention is to have a small slide deck and then go over the documents
13:25:17 mm:
13:26:04 -> https://github.com/w3c/wot/blob/main/planning/Security/README.md wot/planning/Security/README.md
13:27:24 lb: The items in the list probably will go over the 30min alloted
13:32:26 mm:
13:33:05 lb: We aren't many in the TF, we should take the TPAC as chance to enlist more people
13:35:38 kaz: we need to think about deployment environment for actual IoT services like smart homes, smart buildings and smart cities
13:36:07 mm: It's true, but we aren't going to do that during the TPAC
13:36:40 kaz: We could at least reading an issue about detailed security constraints/scenarios
13:39:18 mm: Security is quite horizontal, that applies to most use-cases
13:46:48 lb: I'm concerned about the relationship between the Security TF and the Use-Case TF
13:47:37 lb: Most of the RECs we produce rely on already ratified protocols that bring by themselves security considerations
13:48:03 lb: Most of the historical security concerns come from bad deployments and this is hard to fix
13:50:13 mm: Also the Profile TF might bring security constraints and signal them over profiles as well
13:50:31 lb: It is a good idea IMHO and we could discuss that to TPAC as well
13:52:07 mm: Security experts are busy and valueble, we would use their time to review the other TF outputs
13:53:19 mm:
13:56:07 -> https://www.w3.org/WoT/IG/wiki/Main_WoT_WebConf/2023_WoT_TPAC_Agenda#Security_and_Privacy "Security and Privacy" on the TPAC WoT agenda wiki
13:57:44 [adjourned]