12:04:43 RRSAgent has joined #wot-sec 12:04:43 logging to http://www.w3.org/2017/09/18-wot-sec-irc 12:05:04 Meeting: WoT IG - Security 12:05:28 present: Kaz_Ashimura, Elena_Reshetova, Michael_McCool, Zoltan_Kis 12:05:33 scribenick: kaz 12:06:10 -> https://www.w3.org/2017/09/11-wot-sec-minutes.html prev minutes 12:06:51 Agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Agenda 12:07:18 er: wondering about the workshop thing 12:07:29 mm: IEEE S&P 12:07:36 ... will discuss 12:08:00 topic: Agenda 12:08:18 [[ 12:08:19 WoT Security and Privacy Considerations 12:08:19 Document status and issue review 12:08:19 Security sections in other documents 12:08:19 Document status and issue review 12:08:19 IoT Conference workshop update 12:08:21 NDSS proposal accepted 12:08:23 IEEE S&P deadline: Sept 20 12:08:25 Other work items 12:08:27 ]] 12:08:31 mm: workshop first 12:08:37 topic: Workshop update 12:09:10 barryleiba has joined #wot-sec 12:09:16 mm: NDSS proposal 12:09:22 ... submitted one 12:09:40 ... Decentralized IoT Security and Standards 12:09:47 present+ Barry_Leiba 12:10:00 mm: submitted in parallel 12:10:10 ... had a meeting 12:10:23 ... to merge the two propodals 12:10:28 s/propodals/proposals/ 12:10:38 ... fundamental issue for WoT is interoperability 12:10:49 ... security for multiple interoperable implementations 12:10:57 ... added a couple of topics 12:11:07 ... 3 points 12:11:28 ... Carsten, co-Chair 12:11:50 ... similar proposal on TLS 12:12:08 ... not our primary objective 12:12:28 ... not optimal but still worth presenting our paper 12:12:36 ... get discussion there 12:12:47 ... could get people interested there 12:12:54 ... networking purposes 12:13:23 ... question is if we would like to submit a proposal for IEEE S&P as well 12:13:28 ... deadline Sep. 20 12:13:47 s/submitted one/submitted one and accepted/ 12:13:56 ... can tune it up 12:14:03 ... but should I? 12:14:13 br: think we should 12:14:25 ... target which help our work 12:14:37 mm: right 12:14:41 ... but some concern 12:14:49 ... keep it different from NDSS 12:15:34 ... any other comments? 12:16:06 ... can submit a proposal asis 12:16:12 ... more security people anyhow 12:16:18 ... any suggestions? 12:16:26 ... will circulate the proposal 12:16:40 ... need to wrap up the proposal within 48h 12:16:51 ... you can edit the proposal on Google doc 12:16:58 ... let me know about your Google account 12:17:16 ... will send invitation to you 12:17:28 @McCool My Google Docs account is barryleiba@gmail.com 12:17:28 ... so we'll do this 12:18:05 topic: PR 12:18:16 -> https://github.com/w3c/wot-security/pull/8 Elena's PR 12:18:23 er: goes through it 12:18:45 ... had discussion with Matthias the other day 12:19:33 ... adding pictures 12:19:46 mm: rendered version? 12:21:19 https://rawgit.com/ereshetova/wot-security/working/index.html 12:21:59 kaz: does the above rawgit work fine? 12:22:04 mm: fine 12:22:19 ... contents extracted from the TD draft 12:22:34 ... will work on the pull request 12:23:23 ... one document for security 12:23:36 ... summary within TD, etc. 12:24:46 er: when to have more concrete content? 12:24:57 mm: Thing Description management 12:25:23 ... threat model should go here (Recommended Security Practices) 12:25:37 ... publish this as a Note 12:25:44 ... and put the threat model into it 12:26:36 er: no text under 2.3 yet 12:26:43 ... 2.3 Determining a suitable security architecture 12:27:16 mm: we should put the material here inline 12:27:32 ... need TODOs as Editor's Note 12:28:08 er: this is a working branch, not the main branch 12:28:19 mm: pull request on the working branch 12:28:45 ... will add a tag 12:29:52 ... (adds a tag, "TDmaterial" to the working branch content) 12:30:36 ... (also a branch, "TDmaterial") 12:31:13 ... (and add a comment to the pull request) 12:31:37 ... OK, but we probably want to pull back in the TD material, so I branched as TDmaterial" 12:31:49 s/and/merges the pull request 8 and/ 12:33:19 mm: any procedure to add Elena as an Editor 12:33:36 s/Editor/Editor?/ 12:33:46 zk: you can create a pull request for that? 12:33:49 mm: ok 12:34:09 ... will create a pull request then 12:34:58 ... we can update the link for the threat model 12:35:34 er: can we keep the threat model content a separate file? 12:36:42 mm: there is a trade-off 12:37:32 ... also should think about the references 12:38:05 ... some of the references should go into the draft 12:38:28 -> https://github.com/w3c/wot-security/blob/master/wot-security-references.md references 12:38:46 mm: will create a pull request to put the thread model inline 12:39:59 ... note that I'm working on the master branch and the working branch 12:40:37 ... on the working branch, will put the contents from the MD files into the index.html file 12:41:24 ... let's see an example of the TD repo 12:41:53 ... or the architecture 12:42:22 -> https://w3c.github.io/wot-architecture/ Arechitecture draft on GitHub 12:43:09 mm: we have summary in the main docs 12:43:46 ... remove the Editor's note and put text that we're working on a separate security doc 12:44:48 mm: let's go back to the prev minutes 12:44:51 -> https://www.w3.org/2017/09/11-wot-sec-minutes.html prev minutes 12:44:58 mm: CSS file for a WG Note 12:45:38 kaz: still investigating 12:47:04 ... but we can put NOTE instead of WD/ED for respec 12:47:15 mm: will also see that 12:47:45 ... can we accept the minutes? 12:47:51 (no objections) 12:47:54 mm: ok 12:48:22 -> https://www.w3.org/TR/EARL10-Schema/ example of WG Note 12:49:21 i/let's/topic: Previous minutes/ 12:50:09 topic: Security draft 12:50:15 mm: Abstract is missing 12:50:34 ... Elena, do you want to put a stab? 12:51:13 ... it's the first thing people will read 12:52:12 ... we should submit pull requests for the structure and the individual sections 12:52:34 ... each section can have one pull request 12:52:49 ... will do mechanical edit to include MD file content 12:53:09 ... and Elena will look into the Abstract 12:53:23 ... and then section restructure 12:53:43 ... if there is any conflict, we'll sort that out 12:54:52 er: comments welcome for the structure 12:55:01 mm: where the best practices come from 12:56:57 barryleiba has left #wot-sec 13:02:39 https://rawgit.com/ereshetova/wot-security/working/index.html#threat-model-and-security-objectives 13:05:47 [adjourned] 13:05:54 rrsagent, make log public 13:06:01 rrsagent, draft minutes 13:06:01 I have made the request to generate http://www.w3.org/2017/09/18-wot-sec-minutes.html kaz 14:22:34 Zakim has left #wot-sec