W3C

- DRAFT -

WoT IG - Security

02 Oct 2017

Agenda

See also: IRC log

Attendees

Present
Kaz_Ashimura, Michael_McCool, Michael_Koster, Zoltan_Kis, Barry_Leiba
Regrets
Chair
McCool
Scribe
kaz

Contents


<scribe> scribenick: kaz

Editors group for wot-security github repo

kaz: added Barry to the Editors Team

mccool: wondering about the permission for github
... people from the TF should be able to create issues

Agenda

<scribe> Agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#Agenda

mccool: document status and issues/PRs
... workshop update

PRs

PRs

mccool: get through and try to close them
... starting with PR 26

PR 26

PR 26

mccool: Clean up abstract - related to issue 17

Issue 17

mccool: document here

working branch

mccool: any objections to merge it (=PR 26)?

(none)

mccool: will merge PR 26 then

PR 27

<McCool> https://github.com/w3c/wot-security/pull/27

mccool: next thing is
... threat model
... did some CSS hacking for the table
... definition of terms
... left column is definition
... tried to avoid invisible text
... solution user data/solution provider data
... created new definition
... Malicious Developer-1/Malicious Developer-2 as well
... put Figure 1
... possibly a few things wrong there, though
... bunch of Editor's Notes
... iterate update and generate concrete text based on the Editor's Notes
... need clarifications for some of the terms
... not just tables but cleaned up bunch of stuff
... ok to merge the updates?

(no objections)

mccool: will merge PR 27 then
... going back to issue 16

<McCool> resolves issue #16

<McCool> https://github.com/w3c/wot-security/issues/16

mccool: this issue itself is just for table formatting
... so created another issue 28
... Elena is editing, so want to avoid inconsistency
... would just close issue 16

https://github.com/w3c/wot-security/issues/16 closed now

mccool: and issue 17

https://github.com/w3c/wot-security/issues/17 now closed

PR 24 & 33

PR 24

mccool: there are bunch of MD files
... basically removed them and added hyperlinks
... house keeping things
... OK to merge PR 24?

(no objections)

https://github.com/w3c/wot-security/pull/24 now closed

mccool: will create a new PR

https://github.com/w3c/wot-security/pull/33 merged

mccool: now we have a table for the threat model
... in the spec draft HTML
... there are 2 things from Elena

PR 31

PR 31

mccool: stuff under section 5.1

https://rawgit.com/ereshetova/wot-security/working/index.html#basic-interaction-between-wot-thing-and-wot-client

mccool: RFC draft should be updated with the latest one

changes

mccool: will accept this
... merge and keep it open

https://github.com/w3c/wot-security/pull/31 now merged (but kept as open)

PR 30

mccool: next one

PR 30

mccool: show it to you briefly
... added simple section
... list of suitable references
... still need some more work
... AOB?

<McCool> suggest people also look at this: https://tools.ietf.org/html/draft-irtf-t2trg-iot-seccons-07

mccool: would suggest people look at this

<McCool> I will likely be citing this for "best practices"

<McCool> under review right now...

mccool: would contact the authors
... T2TRG

Issues

mccool: created a few more issues

Issue 18 still pending

mccool: we discussed 19, 20, 21 and need more discussion
... 25 is done

https://github.com/w3c/wot-security/issues/25 now closed

mccool: Issue 32 on Cite WoT Architecture Doc in Intro
... will do
... most of the issues are house keeping ones
... go ahead and create new issues if you are aware of substantial problems
... my actions for the next week is...

<McCool> My actions for next week: work on issue #18, #29, #32, #28

<McCool> at least

https://github.com/w3c/wot-security/issues/18

https://github.com/w3c/wot-security/issues/29

https://github.com/w3c/wot-security/issues/32

https://github.com/w3c/wot-security/issues/28

mccool: need to fill in blank fields
... anything else for today?

(none)

Workshop update

mccool: not got response yet for IEEE workshop

[adjourned]

Summary of Action Items

Summary of Resolutions

[End of minutes]

Minutes formatted by David Booth's scribe.perl version 1.152 (CVS log)
$Date: 2017/10/02 18:02:16 $