12:02:25 RRSAgent has joined #wot-sec 12:02:25 logging to http://www.w3.org/2017/10/09-wot-sec-irc 12:03:05 meeting: WoT IG - Security 12:03:33 present+ Kaz_Ashimura, Michael_McCool, Dave_Raggett, Elena_Reshetova, Zoltan_Kis 12:03:48 Agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Agenda 12:04:41 https://www.w3.org/WoT/IG/wiki/WG_WoT_Thing_Description_WebConf#Agenda 12:05:40 FP Notes 12:05:46 s/Notes/Note/ 12:05:53 and updated Notes 12:06:45 topic: Release Timeline (as a W3C WG Note) 12:06:51 s/WG // 12:07:12 present+ Soumya_Kanti_Datta 12:08:01 Soumya has joined #wot-sec 12:08:04 mm: publication schedule 12:08:11 ... this is a Note 12:08:30 ... distinction on the state of the doc 12:08:33 Mizushima has joined #wot-sec 12:09:14 ... working version and release version 12:09:32 kaz: clarification 12:09:42 mm: would like to publish a first one before TPAC 12:10:00 er: when is TPAC? 12:10:06 kaz: the week of Nov. 6 12:10:40 mm: would like to prepare the release candidate within 2 weeks 12:11:05 ... first draft for the FP Note in 2 weeks from now 12:11:13 ... Oct. 24 12:11:22 ... working -> master 12:12:29 ... and W3C Note: Oct 31 roughly - ready for TPAC Nov. 6 12:13:08 ... (mm checks Elena's availability) 12:13:29 ... 2nd draft: end of Dec 12:13:33 s/Nov. 6/Nov 6/ 12:14:45 ... Dec 19 (Tue) 12:14:51 ... tentatively 12:15:09 ... after that: roughly every 2 months 12:16:01 ... FYI, NDSS deadline Nov 14 12:16:43 ... and the NDSS workshop Feb 18 12:17:03 ... IEEE proposal was rejected 12:17:33 ... I'll be making presentation and need your input for NDSS workshop 12:17:50 ... (going back to the publication schedule) 12:18:00 ... 3rd draft: early Feb 12:18:05 er: might be problematic to m 12:18:11 s/to m/to me/ 12:19:15 mm: 3rd draft: early Feb (e.g., Feb 15 for NDSS; Elena may not be available) 12:19:32 ... (records the above in the wiki) 12:19:35 Release Timeline (W3C Note) First Draft - 2wks from now, Oct 24 (working -> master) W3C Note: FP Note (Oct 31 roughly) - ready for TPAC Nov 6 Second draft: Dec 19 (Tues) Third draft: early Feb (eg Feb 15 for NDSS; Elena may not be available) After that: roughly every two months update 12:19:59 i/after that/kaz: note on the automatic publication system/ 12:20:07 topic: Issues 12:20:46 s/Issues/Pull requests/ 12:20:47 https://github.com/w3c/wot-security/pull/30 12:20:51 topic: Issues 12:20:59 https://github.com/w3c/wot-security/issues 12:21:11 er: submitted proposal for section 5 12:21:19 ... agreement? 12:21:36 ... seems there is some difference 12:21:46 ... need to change the basic assumption? 12:22:14 -> https://rawgit.com/w3c/wot-security/working/index.html#examples-of-wot-security-configurations Section 5 12:22:31 er: ok with this approach? 12:23:34 mm: as long as you're clear with the example, should be ok 12:24:14 er: referring to a couple of RFCs 12:24:59 ... don't want to repeat the descriptions already done by others 12:25:00 ... e.g., OCF 12:25:35 mm: architecture documents include similar things 12:25:42 ... bunch of use cases 12:27:10 ... maybe you could add links referring to the architecture document 12:27:31 er: might be a bit different set 12:27:59 mm: another point you mentioned is OCF 12:28:39 ... WoT client can talk with an OCF device 12:29:30 ... is there a case in which the device doesn't handle WoT TD? 12:30:37 ... one possibility is a Thing itself provides TD 12:31:01 ... or another Thing could provide the TD for the Thing 12:31:30 er: can add some description 12:31:59 q? 12:32:01 q+ 12:32:26 mm: OK with this Editor's Note (Fill in the protocols" 12:32:34 s/protocols"/protocols)/ 12:33:20 present+ Tomoaki_Mizushima 12:33:47 er: any configuration different is important and to be described from security viewpoint 12:34:00 ... would people to submit ideas 12:34:11 mm: we should proceed with some obvious scenarios 12:34:18 ... not too much stuff 12:34:52 ... in this scenario (Fig 3) 12:35:02 ... what if we have a gateway 12:35:23 ... there might be some additional security issue with, e.g., caching 12:35:43 ... need to expand the example to include other possible scenarios 12:36:31 er: btw, the cloud is cut off in Fig 5 12:36:49 ... will work with section 5 tomorrow 12:36:53 q? 12:37:07 mm: we should fix the figure references 12:37:59 ... once you add links to the threats, take a look at the definition 12:39:28 kaz: will we add links to the architecture doc from section 5? 12:39:32 mm: we should do so 12:40:02 ... 1-to-1 link 12:40:15 kaz: do you want to add an Editor's note on that? 12:40:46 mm: (looks at the draft) 12:40:59 ... starting with the section "1. Introduction" 12:41:09 ... will add a link to the WoT Architecture document 12:41:30 ... terminology section also should refer to the Architecture document 12:41:40 i/mm:/mm: as appropriate/ 12:42:20 ack k 12:43:03 mm: still missing content for several sections 12:43:06 er: e.g., 4.2 12:43:17 mm: ok with those sections at the moment 12:43:36 ... should add several abstract sentences, though 12:43:49 ... OK for the first public Note 12:44:28 ... might be going to fix up the formatting for the table 12:44:38 ... to make it consistence 12:44:44 s/consistence/consistent/ 12:45:29 ... let's go back to the issues 12:45:40 topic: Issues 12:45:43 -> https://github.com/w3c/wot-security/issues Issues 12:46:08 mm: Elena has done some edits 12:46:17 https://github.com/w3c/wot-security/issues/29 12:47:33 mm: we have bunch of things with the scenarios 12:47:50 mm: we've done the abstract 12:47:57 https://github.com/w3c/wot-security/issues/17 12:48:46 -> https://rawgit.com/w3c/wot-security/working/index.html#abstract abstract 12:50:05 mm: the abstract is clean enough 12:50:22 kaz: you'll add a link to the Architecture document. right? 12:50:24 mm: yes 12:51:05 ... closes issue 17 12:51:35 ... and create another issue "Align with Architecture document" 12:52:07 https://github.com/w3c/wot-security/issues/35 12:52:42 mm: would like to clean up the document for the first publication within 2 weeks 12:53:12 topic: issue 34 12:53:15 -> https://github.com/w3c/wot-security/issues/34 issue 34 12:53:38 dsr: using WebSocket for Eventing 12:54:00 mm: do you agree with Elena? 12:54:02 dsr: yes 12:54:27 i|Should we have a case for this explained in the "Examples of WoT security configurations" section of the security doc? Seems like a good logical place to describe this case and also talk about the measures 12:54:35 i|yes|Should we have a case for this explained in the "Examples of WoT security configurations" section of the security doc? Seems like a good logical place to describe this case and also talk about the measures| 12:54:53 er: need to clarify concrete mechanism 12:55:18 ... please add description and pictures if possible 12:55:25 ... actual security mitigation, etc. 12:55:38 dsr: wanted to stimulate the discussion 12:56:19 mm: willing to provide concrete text? 12:56:50 s/text/Pullrequest/ 12:56:53 dsr: yes 12:57:03 er: possible new section 5.5 12:57:25 mm: what kind of figure? SVG? 12:57:45 er: please follow the examples from Matthias 12:59:24 mm: good to follow align with existing practices in this space 13:00:00 s|Matthias|Matthias (wot-security/images)| 13:00:28 topic: Issue on privacy 13:00:36 mm: would like to add another issue on privacy 13:00:48 er: we can add a separate section 13:01:09 ... but still need to update the threat model section 13:02:12 ... should add links to the points we need to consider 13:02:19 q+ 13:03:33 kaz: possibly a guy from DAS WG who attended TPAC in Lisbon? 13:03:40 sk: can hep as well 13:03:59 ack k 13:05:18 mm: (can't find Soumya on the list) 13:06:01 mm: who is the guy from DAS? 13:06:03 kaz: @@@ 13:06:48 mm: updates the issue 13:07:17 sk: question on NDSS paper 13:07:50 ... can join the effort as well 13:07:51 mm: tx 13:08:24 i|-> https://github.com/w3c/wot-security/issues/36 Issue 36| 13:08:44 sk: we should have some template 13:08:59 mm: let's have discussion next week 13:09:19 ... (adds a topic on that for the next meeting) 13:09:28 [adjourned] 13:09:42 rrsagent, make log public 13:09:46 rrsagent, draft minutes 13:09:46 I have made the request to generate http://www.w3.org/2017/10/09-wot-sec-minutes.html kaz 13:19:12 elena has joined #wot-sec 13:29:21 zkis has joined #wot-sec 15:09:53 Zakim has left #wot-sec 16:50:43 elena has joined #wot-sec 18:46:39 zkis has joined #wot-sec 18:51:56 elena has joined #wot-sec