12:03:58 RRSAgent has joined #wot-sec 12:03:58 logging to http://www.w3.org/2017/06/30-wot-sec-irc 12:04:38 present+ Elena_Reshetova, Michael_Koster, Michael_McCool, Kaz_Ashimura 12:05:28 meeting: WoT IG - Security 12:07:57 elena: RFC6973 questionnaire 12:08:08 ... generated a google doc for that 12:08:56 mm: first question about stakeholder? 12:09:53 er: and then system maintainer, asset list, ... 12:10:56 ... (goes through the questionnaire list) 12:11:10 ... list of threats complete? 12:11:21 ... security objectives correct? 12:11:39 mm: use cases look more like features 12:12:08 ... would clarify scenario of use use cases 12:12:49 mk: use case being what use is doing 12:13:18 ... so far it seems component-oriented approach 12:13:58 ... we had "atomic use cases" already and that is a bit different kind of use case 12:14:40 ... still struggling about what "security for WoT" 12:14:53 ... there are existing security considerations 12:15:26 ... asking about this questionnaire is a good approach 12:15:59 ... also we should go back to people and ask what they're concerned about WoT security 12:16:29 q+ 12:17:00 er: f2f would be a good opportunity to get people's opinions 12:17:27 mm: we should generate this questionnaire and also should have a session during f2f 12:17:57 ... we need to think about scenario more 12:18:43 present+ Daniel_Ibaseta 12:18:56 ... we have 2 sessions, one is security, another is privacy 12:19:04 ... how to handle them 12:19:10 ... how many sessions should we have? 12:19:19 ... Elena will call in 12:19:24 ... Zoltan will be there f2f 12:19:39 ... 3 hours total maybe? 12:19:51 ... should avoid parallel sessions 12:20:05 er: 1 hour for privacy? 12:20:23 ... the rest 2 hours scenarios 12:20:47 mm: there are already security features in the architecture 12:20:54 ... good to get connected with them 12:21:13 ... we should include scripting people as well 12:21:30 ... half hour for review 12:21:52 er: how many mechanisms? 12:22:07 mm: TLS, secure CoAP, etc. 12:22:14 ... will go back to see the details 12:22:24 ... a section in the TD about security but vague 12:22:49 ... the details should be written in another document and should add a link to that 12:22:58 ... management API 12:23:02 ... isolation 12:23:15 ... would figure out how to evaluate 12:23:27 ... focused discussion with scripting guys 12:23:37 ... 3 hours total 12:23:41 ... 1 hour for privacy 12:23:50 ... security architecture session 12:23:59 ... 1.5 hour for use case scenarios 12:24:11 ... 0.5 for reviewing existing mechanisms 12:24:45 er: we don't have anybody from TD 12:25:02 mm: shows the f2f agenda: https://www.w3.org/WoT/IG/wiki/F2F_meeting,_9-13_July_2017,_D%C3%BCsseldorf,_Germany 12:25:20 ... edits the agenda 12:25:24 ... 1 hour for TD 12:26:32 ... add topics for security 12:26:36 s/add/adds/ 12:28:06 ... 1.5h securiy use cases and scenarios 12:28:19 ... 0.5h review of exisiting/proposed security architecture 12:28:26 ... 1h privacy 12:28:40 topic: Privacy questionnaire 12:29:16 -> Elena's doc file on "Privacy questionnaire for WoT protocol" 12:29:39 q? 12:30:30 er: can modify it 12:30:44 ... and put it a google doc 12:31:15 mm: looks good 12:31:36 er: will apply changes 12:31:47 mm: next Friday, I'll be travelling 12:32:05 mk: will be preparing on that day 12:32:22 mm: would propose we cancel the next meeting 12:32:37 ... we should have a couple of presentation slides for f2f 12:33:15 ... let's skip general background 12:33:37 ... join the openday, and mention the state, etc. 12:33:53 er: can generate some slides and send them to you 12:34:27 mm: introductory explanation probably will be done by Matthias 12:34:28 q? 12:34:44 er: how to distribute the resources? 12:34:50 mm: google doc? 12:35:10 ... would have a link on the security tf page 12:35:38 ... and ask people to review particular documents/questionnaires on the ML 12:35:56 ... to fill out the questionnaire prior to the f2f 12:36:31 q? 12:36:53 ack k 12:37:14 topic: aob 12:37:37 kaz: think we should have security sessions as plenary sessions 12:37:37 mm: agree 12:37:58 ... would add "plenary" mark to those sesssions 12:38:01 s/sss/ss/ 12:39:11 kaz: another question is distributing today's resources to the group list 12:39:31 er: can update the google doc today 12:39:38 ... and send them to you 12:40:38 member-wot-ig@w3.org and member-wot-wg@w3.org 12:42:17 mm: will add hyperlinks to the TF wiki page 12:44:01 kaz: just thought it would be nicer to add concrete resources to the minutes from this call 12:44:11 er: can update the resources and add links to the minutes 12:44:14 [adjourned] 12:44:19 rrsagent, make log public 12:44:44 rrsagent, draft minutes 12:44:44 I have made the request to generate http://www.w3.org/2017/06/30-wot-sec-minutes.html kaz 12:45:13 Chair: McCool 12:51:01 i/RFC6973/topic: Privacy questionnaire - online google doc/ 12:51:03 rrsagent, draft minutes 12:51:03 I have made the request to generate http://www.w3.org/2017/06/30-wot-sec-minutes.html kaz 12:51:39 i/we have 2 sessions/topic: F2F agenda/ 12:51:50 s/aob/AOB/ 12:51:53 rrsagent, draft minutes 12:51:53 I have made the request to generate http://www.w3.org/2017/06/30-wot-sec-minutes.html kaz 15:01:45 Zakim has left #wot-sec