IRC log of wot-sec on 2017-06-30

Timestamps are in UTC.

[kaz]
present+ Elena_Reshetova, Michael_Koster, Michael_McCool, Kaz_Ashimura
[kaz]
meeting: WoT IG - Security
[kaz]
elena: RFC6973 questionnaire
[kaz]
... generated a google doc for that
[kaz]
mm: first question about stakeholder?
[kaz]
er: and then system maintainer, asset list, ...
[kaz]
... (goes through the questionnaire list)
[kaz]
... list of threats complete?
[kaz]
... security objectives correct?
[kaz]
mm: use cases look more like features
[kaz]
... would clarify scenario of use use cases
[kaz]
mk: use case being what use is doing
[kaz]
... so far it seems component-oriented approach
[kaz]
... we had "atomic use cases" already and that is a bit different kind of use case
[kaz]
... still struggling about what "security for WoT"
[kaz]
... there are existing security considerations
[kaz]
... asking about this questionnaire is a good approach
[kaz]
... also we should go back to people and ask what they're concerned about WoT security
[kaz]
[kaz]
er: f2f would be a good opportunity to get people's opinions
[kaz]
mm: we should generate this questionnaire and also should have a session during f2f
[kaz]
... we need to think about scenario more
[kaz]
present+ Daniel_Ibaseta
[kaz]
... we have 2 sessions, one is security, another is privacy
[kaz]
... how to handle them
[kaz]
... how many sessions should we have?
[kaz]
... Elena will call in
[kaz]
... Zoltan will be there f2f
[kaz]
... 3 hours total maybe?
[kaz]
... should avoid parallel sessions
[kaz]
er: 1 hour for privacy?
[kaz]
... the rest 2 hours scenarios
[kaz]
mm: there are already security features in the architecture
[kaz]
... good to get connected with them
[kaz]
... we should include scripting people as well
[kaz]
... half hour for review
[kaz]
er: how many mechanisms?
[kaz]
mm: TLS, secure CoAP, etc.
[kaz]
... will go back to see the details
[kaz]
... a section in the TD about security but vague
[kaz]
... the details should be written in another document and should add a link to that
[kaz]
... management API
[kaz]
... isolation
[kaz]
... would figure out how to evaluate
[kaz]
... focused discussion with scripting guys
[kaz]
... 3 hours total
[kaz]
... 1 hour for privacy
[kaz]
... security architecture session
[kaz]
... 1.5 hour for use case scenarios
[kaz]
... 0.5 for reviewing existing mechanisms
[kaz]
er: we don't have anybody from TD
[kaz]
mm: shows the f2f agenda:,_9-13_July_2017,_D%C3%BCsseldorf,_Germany
[kaz]
... edits the agenda
[kaz]
... 1 hour for TD
[kaz]
... add topics for security
[kaz]
[kaz]
... 1.5h securiy use cases and scenarios
[kaz]
... 0.5h review of exisiting/proposed security architecture
[kaz]
... 1h privacy
[kaz]
topic: Privacy questionnaire
[kaz]
-> Elena's doc file on "Privacy questionnaire for WoT protocol"
[kaz]
[kaz]
er: can modify it
[kaz]
... and put it a google doc
[kaz]
mm: looks good
[kaz]
er: will apply changes
[kaz]
mm: next Friday, I'll be travelling
[kaz]
mk: will be preparing on that day
[kaz]
mm: would propose we cancel the next meeting
[kaz]
... we should have a couple of presentation slides for f2f
[kaz]
... let's skip general background
[kaz]
... join the openday, and mention the state, etc.
[kaz]
er: can generate some slides and send them to you
[kaz]
mm: introductory explanation probably will be done by Matthias
[kaz]
[kaz]
er: how to distribute the resources?
[kaz]
mm: google doc?
[kaz]
... would have a link on the security tf page
[kaz]
... and ask people to review particular documents/questionnaires on the ML
[kaz]
... to fill out the questionnaire prior to the f2f
[kaz]
[kaz]
ack k
[kaz]
topic: aob
[kaz]
kaz: think we should have security sessions as plenary sessions
[kaz]
mm: agree
[kaz]
... would add "plenary" mark to those sesssions
[kaz]
[kaz]
kaz: another question is distributing today's resources to the group list
[kaz]
er: can update the google doc today
[kaz]
... and send them to you
[kaz] and
[kaz]
mm: will add hyperlinks to the TF wiki page
[kaz]
kaz: just thought it would be nicer to add concrete resources to the minutes from this call
[kaz]
er: can update the resources and add links to the minutes
[kaz]
[kaz]
[kaz]
[kaz]
[kaz]
[kaz]
[kaz]
[kaz]
