12:01:01 RRSAgent has joined #wot-sec 12:01:01 logging to http://www.w3.org/2017/09/25-wot-sec-irc 12:01:33 Meeting: WoT IG - Security 12:01:54 present+ Kaz_Ashimura, Michael_McCool, Elena_Reshetova, Uday_Davuluru, Zoltan_Kis 12:03:46 present+ Michael_Koster 12:04:02 present+ Tomoaki_Mizushima 12:04:03 mjkoster has joined #wot-sec 12:06:26 zakim, who is here? 12:06:26 Present: Kaz_Ashimura, Michael_McCool, Elena_Reshetova, Uday_Davuluru, Zoltan_Kis, Michael_Koster, Tomoaki_Mizushima 12:06:29 On IRC I see mjkoster, RRSAgent, Zakim, kaz-win, elena, uday, McCool, kaz, zkis 12:06:49 zakim, pick a scribe 12:06:49 Not knowing who is chairing or who scribed recently, I propose Michael_Koster 12:07:29 scribenick: mjkoster 12:07:29 scribenick mjkoster 12:08:27 Agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Agenda 12:08:48 mccool: document progress update 12:08:59 ... outstanding PR 12:10:11 ... created an action for mccool 12:11:46 ... review the changes in the PR 12:12:07 -> https://github.com/w3c/wot-security/issues Issues 12:12:13 -> https://github.com/w3c/wot-security/pulls Pull Requests 12:12:17 ... ( elena's branch) 12:13:25 elena: recommended practices section 12:14:18 ... example security configuration section 12:15:04 q? 12:15:28 mccool: need to add content for specific security practices e.g. scripting API 12:15:36 -> https://rawgit.com/ereshetova/wot-security/working/index.html Elena's updates 12:17:01 -> https://rawgit.com/w3c/wot-security/working/index.html McCool's Working branch 12:17:26 mccool: would propose we merge Elena's changes to the above Working branch 12:17:31 mccool: merging elena's PR into the working branch now (no objections) 12:18:34 -> https://github.com/w3c/wot-security/pull/12 PR 12 has been merged 12:19:45 https://rawgit.com/w3c/wot-security/working/index.html is updated now 12:20:53 elena: will work on examples (section 5) next 12:22:00 mccool: created issue for tracking additions to the examples section 12:23:14 -> https://github.com/w3c/wot-security/issues issues 12:23:24 mccool: need to add vocabulary definitions 12:24:25 mccool: created issue to track additions to the scenarios section "business/corporate" 12:25:30 ... added issue to track additions to "industrial/commercial" scenarios 12:26:07 ... added issue to track scripting API additions 12:26:36 ... issue to track "validation" 12:27:51 ... discuss whether security provisioning is in scope 12:28:21 elena: we need to make a defined set of assumptions about what is done 12:28:38 ... but can't specify how it's done 12:29:18 mccool: OK 12:29:55 ... please add comments to the issue 12:30:01 q? 12:30:45 mccool: review the discussion on exposed vs. discoverable things 12:30:53 ... are they separate ? 12:31:16 elena: what is the specific difference? 12:32:00 -> https://www.w3.org/2017/09/25-wot-minutes.html discussion during the Scripting call (Member-only) 12:32:07 mccool: different kinds of discovery? 12:33:17 mjkoster: expose means interaction is available, discoverable meand TD is available 12:33:29 s/meand/means 12:33:56 elena: when would a thing be exposed but not discoverable? 12:34:18 mccool: enumerantes types of discovery 12:34:48 ... 4 ways to find a thing 12:35:22 ... may already have a TD or know how to make a URL to get the TD 12:35:39 ... or maybe there is a scan function 12:37:26 mjkoster: consider the difference in security model between TD and the Interactions 12:38:05 elena: how can we define the exact difference between TD and interaction? 12:38:24 mccool: there are different calls in the scripting API 12:39:19 elena: how does the system get into a state where the interactions are available but not discoverable? 12:39:49 s/available/exposed 12:40:29 mccool: things can't be discoverable but not exposed 12:40:36 present+ Soumya_Kanti_Datta 12:42:32 mjkoster: it's about different layers of security for exposure vs. discoverability 12:42:44 elena: OK, that is allowed for in the model 12:44:11 elena: if the proper access control is provided e.g. on actions, then what else do we need to do? 12:44:30 mccool: OK, please continue the discussion in comments and issues 12:45:28 mccool: we need to align the current practices with security mechanisms for the plugfest 12:45:57 ... suggest we look at protocol binding priorities 12:46:35 elena: we should build the scenarios and examples based on concrete protocols 12:47:03 mccool: the statement about wot security includes statements about target protocols 12:47:35 ... if we can cover security through a good comprehensive set of bindings 12:48:22 ... created an issue for tracking 12:48:59 mccool: topic: workshop proposal for NDSS 12:49:14 s/mccool: topic:/topic:/ 12:49:57 ... good response so far 12:50:15 ... most accepted 12:51:30 ... update on IEEE S&P progress 12:51:38 mccool: AOB 12:51:47 elena: on holiday next week 12:52:26 elena: will queue up some material on PR and issues 12:54:24 mccool: would zkis start discussion on the scripting section? 12:54:41 zkis: OK 12:55:11 mccool: adjourn 12:55:27 rrsagent, make log public 12:55:30 rrsagent, draft minutes 12:55:30 I have made the request to generate http://www.w3.org/2017/09/25-wot-sec-minutes.html kaz