IRC log of dap on 2010-03-10

Timestamps are in UTC.

14:38:58 [fjh]
Chair: Robin_Berjon, Frederick_Hirsch
14:39:05 [fjh]
Present+ Robin_Berjon, Frederick_Hirsch
14:39:31 [fjh]
Agenda:
Regrets: Marco_Marengo
14:47:24 [fjh]
Regrets+ Marcin_Hanclik
Present+ Claes_Nilsson
Present+ Suresh_Chitturi
Present+ Ilkka_Oksanen
15:01:06 [dom]
Presen Dominique_Hazael-Massieux
15:01:26 [dom]
Present+ Anssi_Kostiainen
15:02:47 [maxf]
Present+ Max_Froumentin
15:03:05 [nwidell]
Present+ Alissa_Cooper
Present+ Niklas_Widell
15:04:14 [jmorris]
Present+ John_Morris
Present+ Dzung_Tran
zakim, who is here?
15:04:37 [Zakim]
On the phone I see fjh, ilkka, suresh, Dom (muted), AnssiK, richt, maxf (muted), Claes, jmarting_TEF, darobin (muted), Niklas
15:04:39 [Zakim]
On IRC I see richt, Dzung_Tran, jmorris, nwidell, AnssiK, alissa, Suresh, Claes, rvazquez, darobin, Zakim, RRSAgent, tlr, Marcos, maxf, fjh, ilkka, arve, blassey, shepazu,
15:04:41 [Zakim]
... trackbot, dom
ScribeNick: alissa
15:05:52 [fjh]
Topic: Administrative
present+ Paddy_Byers
15:06:29 [richt]
Present+ Richard_Tibbett
15:07:56 [fjh]
F2F 16-18 March
15:08:10 [RuthVazquez]
RuthVazquez has joined #dap
15:08:15 [fjh]
F2F logistics:
15:08:35 [fjh]
* Note on Daylight savings time difference between US and EU,
15:08:43 [fjh]
15:09:18 [fjh]
proposed RESOLUTION: Cancel teleconference 24 March
15:09:18 [darobin]
[note that some calendar programs (such as iCal) allow you to anchor meetings in a TZ, in this case use US Eastern]
15:09:22 [maxf]
as mentioned in the above email, is a good resource
15:09:36 [alissa]
RESOLUTION: Cancel teleconference 24 March
15:09:52 [fjh]
2c) possible F2F at TPAC, Thur/Fri 4-5 November,
15:10:11 [dom]
15:10:15 [dom]
ack me
15:10:17 [fjh]
ack dom
15:11:01 [alissa]
dom: not sure if thurs-fri is best for TPAC meeting
15:11:15 [alissa]
... depends on joint meetings with other groups
15:11:25 [alissa]
fjh: works better for me thurs-fri
15:11:45 [alissa]
... can we indicate tentative preference for thurs-fri?
15:12:05 [aguillou]
Present+ aurelien_guillou
15:12:20 [alissa]
dom: can we say we're flexible but have a conflict with XML Security?
15:12:33 [alissa]
... and that we want to meet with Geoloc and Web Apps?
15:12:35 [jmorris]
15:12:41 [fjh]
ack jmorris
15:13:57 [alissa]
darobin: will indicate thurs-fri preference
15:14:02 [alissa]
Topic: Minutes approval
15:14:05 [fjh]
3 March 2010
15:14:13 [fjh]
15:14:20 [fjh]
proposed RESOLUTION: Minutes from 3 March approved.
15:14:25 [alissa]
RESOLUTION: Cancel teleconference 24 March
15:14:33 [alissa]
Topic: F2F Agenda
15:14:49 [alissa]
fjh: moved some privacy stuff to the first day to accommodate alissa
15:14:49 [fjh]
15:15:15 [alissa]
... nobody from Google will be attending
15:15:37 [fjh]
Day 1, Tuesday, 16 March (10:00 - 17:00)
15:15:37 [fjh]
Day 2, Wednesday 17 March (9:00 - 17:30)
15:15:50 [fjh]
Day 3, Thursday 18 March (9-15:30)
15:16:42 [alissa]
no concerns raised about times
fjh: concerned that we're sitting on submissions, try to use F2F to get something going with policy
15:17:52 [Suresh]
15:18:59 [alissa]
fjh: more time for contacts as it's an important API
15:19:26 [richt]
Though nothing has been proposed (yet) on the mailing list I have an action to write up the OpenProvider proposal before the F2F. It would be nice if we have time to discuss this.
15:19:26 [fjh]
ack suresh
15:19:53 [fjh]
15:19:53 [trackbot]
ACTION-48 -- Suresh Chitturi to propose a definition for API access control, and a possible model for policy enforcement -- due 2010-02-24 -- CLOSED
15:19:53 [trackbot]
15:20:14 [alissa]
Suresh: ACTION-48 has not been incorporated
... access control definition has not been discussed
15:20:41 [alissa]
... could be done at F2F
15:20:59 [LauraA]
Present+ LauraA
15:21:02 [dom]
present+ David_Rogers
15:21:36 [fjh]
action: add definition from ACTION-48 to policy requirements
15:21:36 [trackbot]
Sorry, couldn't find user - add
15:21:48 [fjh]
action: fjh to add definition from ACTION-48 to policy requirements
15:21:48 [trackbot]
Created ACTION-102 - Add definition from ACTION-48 to policy requirements [on Frederick Hirsch - due 2010-03-17].
15:22:01 [fjh]
s/action: add.*//
q+ To ask if we could allocate some time for OpenProvider in the F2F agenda
15:22:36 [fjh]
ack richt
15:22:36 [Zakim]
richt, you wanted to ask if we could allocate some time for OpenProvider in the F2F agenda
15:22:52 [alissa]
richt: can we get some time to discuss OpenProvider at the F2F?
15:23:08 [alissa]
... proposal went to the list
15:23:25 [alissa]
... proposal WILL GO to the list this friday
15:23:45 [alissa]
fjh: can discuss in conjunction with powerbox
15:24:06 [fjh]
s/proposal went to the list//
15:24:40 [fjh]
reminder - to discuss OpenProvider during F2F, presumably in conjunction with Powerbox discussion
15:25:15 [fjh]
15:26:18 [alissa]
fjh: no speakerphone for F2F, so remote participants will need patience
15:26:30 [Claes]
During the Powerbox discussion it would be good to have Google on the bridge
15:26:36 [alissa]
... remote participants should go onto IRC and say when they are planning to call in
15:27:36 [alissa]
darobin: we have an address and a room, it's all on the wiki
15:27:57 [alissa]
Topic: Editorial
15:28:18 [alissa]
fjh: maxf proposed separating use cases from APIs
15:28:29 [fjh] (Max)
15:29:13 [alissa]
maxf: implemented the split in systems info
15:29:30 [alissa]
... to do use cases and requirements properly it takes a lot of space
15:29:47 [alissa]
... drawback is that if you want to publish it, you must publish separate document
15:30:00 [alissa]
... but still thing split is better. each editor could decide.
15:30:20 [alissa]
fjh: no preference really
15:30:26 [dom]
+1 to splitting use cases out, don't feel strongly that we need to publish them as TR
15:30:36 [darobin]
+1 to what dom said
15:30:43 [maxf]
15:30:52 [alissa]
fjh: will decide on case-by-case basis
15:31:06 [alissa]
Topic: Policy
15:31:33 [alissa]
it's fine
15:31:59 [alissa]
fjh: editorial change to policy section to make requirements types explicit
15:32:12 [fjh]
action: fjh to update policy requirements revising T*
15:32:12 [trackbot]
Created ACTION-103 - Update policy requirements revising T* [on Frederick Hirsch - due 2010-03-17].
15:32:18 [alissa]
fjh: prefer use cases in published documents
15:32:58 [fjh]
15:33:36 [Dzung_Tran]
+1 for use cases in published documents
15:33:40 [jmorris]
alissa: discussing apps informing users of what their policies are
15:33:53 [fjh]
15:34:19 [fjh]
general agreement about talking about substance of policy, not ui (for now)
15:35:02 [fjh]
15:35:06 [fjh]
15:35:06 [trackbot]
ISSUE-73 -- Security and Privacy Implications for PIM APIs -- OPEN
15:35:06 [trackbot]
15:35:25 [alissa]
Topic: ISSUE-73
15:35:49 [alissa]
David: had been looking at use cases
15:35:50 [dom]
15:35:50 [trackbot]
ACTION-45 -- David Rogers to provide use case with threat model scenarios -- due 2010-03-10 -- OPEN
15:35:50 [trackbot]
15:36:17 [alissa]
... matching policy parts to abuse case
15:36:30 [alissa]
... e.g., voicemail number changed to premium rate number
15:36:48 [alissa]
...hope to circulate tomorrow or friday
15:37:09 [richt]
15:37:18 [alissa]
... trying to show how to resolve abuses with BONDi policy
15:37:19 [fjh]
ISSUE-73: see ACTION-45
15:37:19 [trackbot]
ISSUE-73 Security and Privacy Implications for PIM APIs notes added
15:37:27 [fjh]
ack richt
15:37:28 [richt]
ISSUE-73 discussion: 'Contacts API typical use cases and privacy considerations'
15:37:51 [alissa]
richt: had a good discussion with dom, should inform abuse cases
15:37:53 [fjh]
ISSUE-73: see also
15:37:53 [trackbot]
ISSUE-73 Security and Privacy Implications for PIM APIs notes added
15:38:13 [alissa]
... auto-filling the form
15:38:39 [alissa]
fjh: still not sure if we've dealt with policy concerns for that case
15:39:25 [alissa]
David: have not considered auto-form filling use case yet
15:39:38 [alissa]
fjh: will want to talk about that at the F2F
15:39:55 [alissa]
David: if we can maintain a list of abuse cases and threat model going forward, we should do that
15:40:16 [alissa]
... don't want to be repeating core threats all the time
15:41:14 [alissa]
... if user makes stupid decision, that's out of the control of the API
15:41:28 [alissa]
... might need a section on user's responsibility to themselves
15:41:47 [fjh]
15:41:48 [trackbot]
ISSUE-37 -- Domain spoofing and trust in the network layer -- OPEN
15:41:48 [trackbot]
15:42:06 [alissa]
Topic: ISSUE-37 domain spoofing and trust in the network layer
15:42:16 [fjh]
15:42:16 [trackbot]
ACTION-38 -- Claes Nilsson to should issue recommendation on the granularity of the security system -- due 2009-12-16 -- CLOSED
15:42:16 [trackbot]
David: we need to consider connecting to wifi in a cafe or airport and resulting security threats
15:43:30 [alissa]
... persistent connection to mobile provider is more secure at the moment
15:43:45 [alissa]
... tlr disagrees
15:44:11 [alissa]
... there are a couple of demos
... of domain spoofing
15:44:42 [alissa]
paddy: this boils down to abuse cases again
15:45:01 [fjh]
15:45:57 [alissa]
David: can add this aspect
15:46:19 [fjh]
action: drogersuk to add use case related to ISSUE-37
15:46:19 [trackbot]
Sorry, couldn't find user - drogersuk
15:46:31 [dom]
action: roger to add use case related to ISSUE-37
15:46:31 [trackbot]
Sorry, couldn't find user - roger
15:46:37 [dom]
action: rogers to add use case related to ISSUE-37
15:46:37 [trackbot]
Created ACTION-104 - Add use case related to ISSUE-37 [on David Rogers - due 2010-03-17].
15:47:06 [alissa]
Topic: update to FileWriter
15:47:08 [darobin]
15:48:00 [dom]
+1 to send a CfC on FileWriter
15:48:03 [alissa]
darobin: ready for FPWD at F2F?
15:48:07 [richt]
15:48:12 [darobin]
ack richt
15:48:33 [alissa]
richt: it's not using namespacing -- do we need it?
15:48:57 [alissa]
darobin: first decision was to do it case-by-case
15:49:11 [alissa]
... more impt to have consistency with file API in this case
15:49:45 [alissa]
richt: not concerned, just wondering if it affects other APIs
15:49:46 [dom]
[I don't think that question should block FPWD in any cas€]
15:49:54 [alissa]
darobin: depends on the case
15:50:26 [alissa]
... have not been able to get any agreement otherwise
15:50:32 [alissa]
... agree that it shouldn't block FPWD
15:50:41 [richt]
richt: agreed
darobin: style of writing API descriptions -- normative statements can be clunky but we might want them
15:51:11 [darobin]
ack David
15:51:31 [alissa]
David: Martin submitted design patterns document that might be helpful
15:51:39 [darobin]
15:51:48 [alissa]
sorry about the names
15:51:55 [dom]
(last update to design patterns was in October)
15:52:11 [alissa]
darobin: hasn't been updated since BONDI?
15:52:26 [alissa]
... can talk to him about picking it up
15:52:33 [darobin]
15:52:33 [dom]
15:52:52 [dom]
-> Marcin's draft on API Design Patterns
15:53:08 [alissa]
Topic: update to Messaging
15:53:10 [darobin]
15:53:24 [maxf]
15:53:54 [alissa]
maxf: looks perfect to me
15:53:59 [dom]
[I read through it, I think it's in good shape generally speaking]
15:55:14 [alissa]
nwidell: will not be at F2F
15:55:20 [alissa]
darobin: no isue with publishing it
15:55:30 [alissa]
15:55:48 [alissa]
nwidell: would appreciate comments
15:56:00 [alissa]
darobin: asking for publication will accomplish that - CfC
15:56:29 [alissa]
nwidell: will make editorial changes by monday
15:56:59 [alissa]
... go ahead to CfC now
15:57:25 [alissa]
darobin will send CfC after call
Topic: System Info next steps
15:57:38 [darobin]
ack Suresh
15:58:10 [darobin]
15:58:16 [alissa]
Suresh: Calendar API has been sitting around for a month now
15:58:46 [alissa]
... action out on harmonizing with IETF, that work is complementary
15:58:46 [richt]
I agree with Suresh
15:58:56 [alissa]
... want to go to FPWD
15:59:27 [alissa]
... will add a note about the compatability issue
15:59:48 [alissa]
darobin will send CfC for calendars as well
16:00:13 [alissa]
dom: mapping may not be complementary
16:00:47 [alissa]
... may not have consistent view of scope of Calendar API
16:01:32 [alissa]
Suresh: we don't cover entire set of cases, it's true
16:01:46 [alissa]
... but have placeholders for most items
16:02:09 [alissa]
dom: agreed
16:02:15 [richt]
there's some...interesting...stuff in the Calendar API...will need a thorough review and welcome further comments before or during the F2F
16:02:20 [alissa]
... withdraw my comment
16:02:25 [dom]
16:02:47 [dom]
[I don't think all my comments have been integrated in the calendar API; hence why I haven't further commented on it, FWIW]
16:02:51 [alissa]
Topic: System Info
16:03:05 [alissa]
maxf: mapping to DCO, thresholds are outstanding issues
16:03:27 [alissa]
... prepped a list of items to discuss at F2F
16:03:52 [fjh]
q+ to ask about ACTION-100
16:04:09 [darobin]
16:04:09 [trackbot]
ACTION-100 -- John Morris to share information on key important privacy policy aspects relevant to DAP -- due 2010-03-10 -- OPEN
16:04:09 [trackbot]
16:04:23 [fjh]
16:04:23 [trackbot]
ACTION-100 -- John Morris to share information on key important privacy policy aspects relevant to DAP -- due 2010-03-10 -- OPEN
16:04:23 [trackbot]
16:04:50 [alissa]
fjh: is action-100 still open?
16:05:02 [alissa]
jmorris: will have something but perhaps not until monday
16:05:55 [alissa]
... walking through different APIs to suggest which privacy issues are most importance
16:06:15 [alissa]
... can get something higher level out earlier and more granular later on
16:06:59 [alissa]
no problem
Present+ Dominique_Hazaël-Massieux
