IRC log of dap on 2010-04-07

Timestamps are in UTC.

13:32:44 [fjh]
Chair: Robin_Berjon, Frederick_Hirsch
13:32:53 [fjh]
Present: Robin_Berjon, Frederick_Hirsch


Regrets: Dominique_Hazaƫl-Massieux, Ilkka_Oksanen, Thomas_Roessler
Present+ John_Morris
Present+ John_Morris
jmorris has joined #dap
I'll scribe
thanks paddy!
scribenick: paddy
Topic: Administrative
14:05:56 [fjh]
Updated Capture API draft published, 1 April 2010
14:06:04 [fjh]
14:06:06 [aguillou]
Present+ Aurelien_Guillou
14:06:11 [fjh]
FPWD of File API: Writer published, 6 April 2010
14:06:13 [Zakim]
14:06:19 [fjh]
14:06:21 [richt]
richt has joined #dap
14:06:24 [fjh]
Topic: Minutes
14:06:26 [paddy]
fjh: minutes are out: any changes wanted?
14:06:31 [richt]
Present+ Richard_Tibbett
14:06:36 [fjh]
14:06:43 [Zakim]
+ +1.408.216.aaff
14:06:45 [paddy]
RESOLUTION: minutes of 31 March approved
14:06:55 [fjh]
Topic: Policy
14:07:03 [Suresh]
Suresh has joined #dap
14:07:05 [ingmar]
Present+ Ingmar_Kliche
14:07:08 [fjh]
14:07:15 [fjh]
14:07:15 [trackbot]
ACTION-153 -- Alissa Cooper to refine privacy requirements (with John) -- due 2010-04-07 -- OPEN
14:07:15 [trackbot]
14:07:15 [paddy]
fjh: Had actions to review requirements - Alissa, do you have anything to say?
14:07:24 [Suresh]
Suresh has joined #dap
14:07:29 [paddy]
alissa: I tried to pare down to just talking about the requirements on APIs
14:07:34 [wonsuk]
wonsuk has joined #dap
14:07:36 [Suresh]
Present+ Suresh_Chitturi
14:07:36 [fjh]
comments from Frederick at
14:07:49 [paddy]
.. we decided to separate from policy stuff and best practices for app developers
14:07:52 [wonsuk]
Present+ Wonsuk_Lee
14:07:54 [fjh]
updated editors draft with this revision, see
14:07:58 [paddy]
.. decided just to adjust text without changing too much
14:08:14 [fjh]
Previous versions are visible in the CVS history
14:08:20 [paddy]
.. did some other editorial changes: tried to fill in big table with other elements of privacy
14:08:22 [fjh]
14:08:45 [paddy]
.. I just don't think that the complete picture of what gets addressed where is obvious
14:09:16 [paddy]
jmorris: I thinkit would be helpful to have a couple of diagrams on architecture as discussed in Prague
14:09:35 [paddy]
fjh: alissa,, were you proposing additional text to address that?
14:09:44 [Zakim]
14:09:50 [paddy]
.. just to make sure new readers understand what we are trying to do
14:09:57 [darobin]
-> some unfinished noodling
14:10:00 [paddy]
.. we do need to have a bit more to set out scope, context
14:10:16 [paddy]
jmorris: do we do it in this document? My personal vote is yes
14:10:27 [paddy]
fjh: yes, don't want to proliferate documents unnecessarily
14:10:50 [paddy]
darobin: I have an action to look at separate solutions, have drafted some text in a separate document
14:11:07 [fjh]
Robin suggests using material from background section
14:11:11 [paddy]
... are you looking for something like what's in the background section of that document?
14:11:21 [fjh]
14:11:32 [paddy]
alissa: yes, I think if something like this doc exists, then the API requirements doc can refer to it
14:12:03 [paddy]
jmorris: I don't think we need explanation in every doc; but should be somewhere publically visible when we first publish
14:12:13 [paddy]
.. alissa and I can look at it, but it's a good start
14:12:35 [fjh]
I suggest we copy background section from Robin's draft into requirements document
14:12:36 [paddy]
darobin: doc was just a brain dump, so steal the text and put in the requirements doc
14:13:00 [paddy]
fjh: alissa, jmorris: do you wish to take on editorial control?
14:13:01 [darobin]
+1 to either or both alissa and jmorris to have editorial access
14:13:12 [paddy]
jmorris: I think it should be alissa
14:13:43 [fjh]
action: fjh to add background section into requirements with some edits
14:13:43 [trackbot]
Created ACTION-157 - Add background section into requirements with some edits [on Frederick Hirsch - due 2010-04-14].
14:13:50 [hendry]
darobin: review the text before copying it :)
14:14:09 [paddy]
.. dom will set up access for editing
14:14:30 [paddy]
fjh: took out abuse cases; some of this might be in the requirements doc
14:14:41 [paddy]
.. do you want to review how it relates to your part?
14:14:53 [richt]
14:14:54 [paddy]
alissa: I can review but also welcome suggestions from the list
14:15:17 [paddy]
fjh: is there more to be said about this?
14:15:36 [richt]
q+ to talk about latest addition to Contacts API:
14:15:38 [paddy]
... next step is to decide what we do in the various API docs
14:15:40 [Zakim]
14:16:17 [paddy]
alissa: do we want the privacy issues to be explicit requirements on the APIs?
14:16:19 [danielcoloma]
Present+ DanielColoma
14:16:39 [fjh]
I believe api docs should each list the privacy items and how they are addressed
14:16:44 [paddy]
... I think there should be, but others may disagree
14:16:47 [darobin]
14:16:54 [paddy]
fjh: agree it should be explicit as requirements
14:17:09 [paddy]
.. then we can determine the degree to which each API satisfies those requirements
14:17:24 [paddy]
.. also we need a caveat about privacy requirements changing
14:17:38 [paddy]
bryan: I agree should indicate the scope of the requirements in the API docs
14:17:55 [paddy]
.. but there should be a central place where the concepts, requirements are discussed in general terms
14:18:00 [darobin]
14:18:04 [fjh]
each api should indicate how it supports or does not support, items in API table
14:18:06 [darobin]
ack richt
14:18:06 [Zakim]
richt, you wanted to talk about latest addition to Contacts API:
14:18:10 [paddy]
richt: I added a section to contacts API to try out this idea
14:18:27 [paddy]
.. to discuss issues relating to privacy and also other design considerations relating to the API
14:18:36 [paddy]
.. added section "privacy by design"
14:18:36 [fjh]
14:19:00 [paddy]
.. but done in parallel to what has been happening in the privacy requirements document
14:19:22 [paddy]
richt: .. it would be great to get feedback, this is just embryonic at this stage
14:19:36 [fjh]
maybe we should focus on contacts first, then revise other docs with similar agreed model
14:19:51 [paddy]
... quite useful to have as design considerations explicitly tailored to the requirements/issues of each API
14:20:03 [paddy]
.. every API has different issues
14:20:17 [fjh]
ok, so start is to get the facts for each API, then worry about formatting
14:20:27 [darobin]
14:20:42 [paddy]
fjh: get the facts down in each doc first, then worry about formatting
14:21:00 [paddy]
... if each API doc owner can create a privacy section, this will be a good starting point
14:21:09 [paddy]
.. thanks to richt for this input
14:21:35 [paddy]
.. next step for privacy will be to go through each API
14:21:39 [paddy]
.. add background section
14:21:44 [paddy]
... review the big table
14:21:51 [paddy]
... decide what needs to be added in
14:22:22 [paddy]
.. alissa, jmorris, did you have concerns about the text? were you going to do something about that?
14:23:00 [paddy]
.. what is the size of the concern, and when will we have an update?
14:23:12 [paddy]
jmorris: concerns were mostly minor
14:23:48 [paddy]
... there were multiple contributors, and existing text is raising questions/issues rather than being presented logically
14:24:01 [paddy]
alissa: jmorris should forward proposed changes to list
14:24:23 [paddy]
fjh: trying to figure out what needs to happen before we can make a public draft
14:24:38 [paddy]
jmorris: can send input to list in next few days
14:24:48 [paddy]
fjh: licensing stuff as well?
14:24:56 [fjh]
action: jmorris to send proposed changes to list re privacy requirements
14:24:57 [trackbot]
Created ACTION-158 - Send proposed changes to list re privacy requirements [on John Morris - due 2010-04-14].
14:24:58 [paddy]
alissa: need more time for that part
14:25:06 [paddy]
fjh: achievable this month?
14:25:33 [paddy]
fjh: more comments on that requirements doc?
14:25:51 [fjh]
Topic: Policy Framework
14:25:56 [paddy]
fjh: Laura, you did some edits on the policy framework - do you want to talk to what you did?
14:26:01 [fjh]
14:26:01 [trackbot]
ACTION-152 -- Laura Arribas to edit policy framework, reviewing BONDI material and editorial update -- due 2010-04-07 -- OPEN
14:26:01 [trackbot]
14:26:03 [paddy]
laura: yes
14:26:12 [maoteo]
maoteo has joined #dap
14:26:23 [paddy]
.. I continued what drogers started, based on input from BONDI
14:27:43 [paddy]
... will email the list when ready for review
14:28:03 [fjh]
14:28:03 [trackbot]
ISSUE-79 -- Fingerprinting privacy issue related to sysinfo, need for feedback on privacy risk -- OPEN
14:28:03 [trackbot]
14:28:11 [paddy]
fjh: can we make progress on other policy issues?
14:28:29 [paddy]
... do we have a solution to this issue? I'm not sure what we want to do
14:28:39 [paddy]
... is anyone thinking about this?
14:28:54 [paddy]
... I'm going to suggest that we focus on the functionality of sysinfo
14:29:01 [paddy]
... maxf - are you the editor?
14:29:06 [maxf]
zakim, unmute me
14:29:06 [Zakim]
maxf should no longer be muted
14:29:24 [fjh]
perhaps this is a minimization issue
14:29:27 [paddy]
jmorris: I think it is right to address via minimisation
14:29:46 [paddy]
fjh: then we do have a way to address it, so we have to talk about minimisation
14:30:00 [fjh]
action: maxf note minimization in sysinfo to address ISSUE-79
14:30:00 [trackbot]
Created ACTION-159 - Note minimization in sysinfo to address ISSUE-79 [on Max Froumentin - due 2010-04-14].
14:30:06 [maxf]
I'll try again
14:30:12 [maxf]
and hang up
14:30:22 [Zakim]
14:30:22 [fjh]
zakim, who is here?
14:30:23 [Zakim]
On the phone I see marengo (muted), fjh, alissa, bryan, darobin, Claes, drogersuk, paddy, Ingmar_Kliche, richt, richt.a, +1.408.216.aaff, danielcoloma (muted), LauraA, wonsuk
14:30:28 [Zakim]
alissa has john_morris
14:30:30 [Zakim]
On IRC I see maoteo, danielcoloma, hendry, wonsuk, Suresh, richt, aguillou, jmorris, LauraA, Dzung_Tran, paddy, drogersuk, Claes, alissa, marengo, darobin, Kangchan, arve, Zakim,
14:30:33 [Zakim]
... RRSAgent, fjh, Marcos, tlr, maxf, ingmar, ilkka, shepazu, trackbot, dom
14:30:44 [paddy]
darobin: one thing that worries me is that the document is mature and nearly ready for LC
14:30:46 [maxf]
to answer the question, I am the editor and I've not thought about policy much
14:30:52 [paddy]
.. so we need to address this issue before LC
14:31:02 [paddy]
.. so we don't carry the issue into LC
14:31:21 [paddy]
.. perhaps the resolution is simple, but it still needs to be written up
14:31:46 [paddy]
fjh: we need to say how it is addressed, eg the API design permits incomplete responses
14:32:09 [paddy]
darobin: currently in the API, it is an implementation decision as to what information is returned
14:32:12 [fjh]
need note to warn implementations about need for minimization
14:32:20 [fjh]
zakim, who is here?
14:32:20 [Zakim]
On the phone I see marengo (muted), fjh, alissa, bryan, darobin, Claes, drogersuk, paddy, Ingmar_Kliche, richt, richt.a, +1.408.216.aaff, danielcoloma (muted), LauraA, wonsuk
14:32:23 [Zakim]
alissa has john_morris
14:32:24 [Zakim]
On IRC I see maoteo, danielcoloma, hendry, wonsuk, Suresh, richt, aguillou, jmorris, LauraA, Dzung_Tran, paddy, drogersuk, Claes, alissa, marengo, darobin, Kangchan, arve, Zakim,
14:32:24 [paddy]
fjh: so we have an implementation guideline
14:32:26 [Zakim]
... RRSAgent, fjh, Marcos, tlr, maxf, ingmar, ilkka, shepazu, trackbot, dom
14:32:27 [Zakim]
14:33:16 [darobin]
[I think that adding concerns of fingerprinting and minimisation to might be enough]
14:33:24 [paddy]
fjh: need a paragraph in the doc saying the minimisation is important, and implementations may make minimised responses
14:33:34 [paddy]
.. not necessarily controlled via policy
14:33:52 [paddy]
... darobin says address it before LC
14:33:55 [paddy]
maxf: ok
14:34:00 [fjh]
14:34:00 [trackbot]
ISSUE-38 -- Use cases and threat model for security requirements -- OPEN
14:34:00 [trackbot]
14:34:02 [maxf]
zakim, mute me
14:34:02 [Zakim]
maxf should now be muted
14:34:15 [paddy]
fjh: other issue is about use cases and threat model
14:34:29 [paddy]
... drogers did something, is there more we need to do?
14:34:49 [paddy]
drogers: had to take a week off so unable to progress as intended
14:35:11 [fjh]
david notes that we need linkages from threats to requirements
14:35:12 [paddy]
... but have agreed to put a placeholder in the policy document so policy requirements are traceable back to threats
14:35:24 [paddy]
fjh: will you do a proposal for that?
14:35:34 [paddy]
drogers: yes, I will be able to progress soon
14:35:50 [paddy]
... already captured in existing action
14:35:56 [fjh]
14:35:56 [trackbot]
ISSUE-37 -- Domain spoofing and trust in the network layer -- OPEN
14:35:56 [trackbot]
14:36:02 [paddy]
fjh: another issue - out of scope?
14:36:13 [paddy]
... network layer, different layers of protocol stack
14:36:27 [paddy]
... and threats arising from network-layer attacks
14:36:31 [paddy]
... is this in scope?
14:36:44 [paddy]
drigers: yes, eg 3G vs Wifi
14:36:53 [fjh]
14:37:05 [fjh]
david notes he will capture in threats, then we can discuss
14:37:09 [paddy]
... need to capture in threats, and important consideration
14:37:20 [paddy]
.. but decision will be later as to whether or not in scope
14:37:26 [fjh]
14:37:26 [trackbot]
ISSUE-17 -- Summarize security issues and related requirements for file API -- OPEN
14:37:26 [trackbot]
14:37:51 [paddy]
fjh: issue 17 - should deal with file API - probably need to work on this
14:38:00 [paddy]
... but can't remember the status
14:38:07 [paddy]
... any comment?
14:38:34 [paddy]
Topic: APIs
14:38:48 [paddy]
darobin: hasn't been a whole lot of progress in last week
14:39:04 [paddy]
... one issue: rename "capture" to "media capture"
14:39:18 [paddy]
RESOLUTION: change "capture" to "media capture"
14:39:29 [fjh]
but no change to shortname
14:39:33 [paddy]
darobin: we published capture and file writer
14:39:53 [paddy]
... hopefully getting some feedback
14:40:08 [paddy]
... richt, anything new on contacts you want to bring up?
14:40:27 [paddy]
richt: only really did the privacy section
14:40:35 [paddy]
... not many other changes
14:40:46 [paddy]
... similarly calendar is progressing, but slowly
14:41:00 [paddy]
darobin: will update the docs based on what we agreed today?
14:41:02 [paddy]
richt: sure
14:41:09 [maxf]
zakim, unmute me
14:41:09 [Zakim]
maxf should no longer be muted
14:41:20 [paddy]
darobin: maxf indicated that changes agreed at f2f in messaging are addressed
14:41:28 [paddy]
... is that true?
14:41:48 [paddy]
maxf: yes, did first part of changes but not much time in last couple of weeks
14:41:56 [paddy]
... committed some changes this morning
14:42:10 [paddy]
... so should now be synchronised with what was agreed at f2f
14:42:29 [paddy]
darobin: doc seems to be broken, some styling isn't working
14:42:42 [richt]
FYI, messaging URL:
14:42:52 [David]
... also we agreed removing section 7 as it relates more to application launcher
14:43:16 [paddy]
maxf: I should have checked, that wasn't implemented in draft
14:43:28 [paddy]
darobin: would this then be ready for publication next week?
14:43:31 [paddy]
maxf: yes
14:43:54 [paddy]
darobin: as soon as checks are completed, send an email and we will issue CfC
14:44:19 [paddy]
... lets look at sysinfo
14:44:28 [paddy]
maxf: did changes discussed at f2f
14:44:56 [paddy]
... there are 2 or 3 things still to do, but should be really quick to complete it
14:46:31 [paddy]
.. if there's nothing else in terms of progress on APIs, suggest move to AOB
14:46:40 [paddy]
Topic: AOB
14:46:53 [paddy]
fjh: edits to ReSpec - will this break our docs?
14:47:07 [fjh]
14:47:14 [paddy]
darobin: this should not break anything, but report any problems you see
14:47:38 [paddy]
... there are at least 4 or 5 other groups using ReSpec but these have added nice new features
14:47:46 [richt]
q+ check on ACTION-120 status -
14:47:49 [paddy]
... anything else?
14:47:55 [darobin]
14:47:55 [trackbot]
ACTION-120 -- Robin Berjon to check with Geolocation WG re choice of object literals vs positional parameters in geo API -- due 2010-03-24 -- OPEN
14:47:55 [trackbot]
14:47:59 [paddy]
richt: wanted to focus on action 120
14:48:15 [paddy]
... related to style of these APIs - does this have significant impact on publication?
14:48:36 [paddy]
darobin: will do it now
14:49:10 [paddy]
.. hope we don't get bogged down in long discussion on API styles
jmorris has joined #dap
