W3C

WoT Security

22 February 2021

Attendees

Present
Cristiano_Aguzzi, Elena_Reshetova, Kaz_Ashimura, Michael_McCool, Philipp_Blum, Tomoaki_Mizushima
Regrets
Oliver
Chair
McCool
Scribe
citrullin

Meeting minutes

<kaz> Feb-15

McCool: Checking minutes from last time.

Philipp: Doesn't make it sense to have the discussion about MCUs etc. in Architecture.

McCool: Yes, that is part of it.

Any objections for the minutes?

No objections

McCool: Any quick updates?

None

<McCool> https://github.com/w3c/wot-thing-description/pull/1058

Add Json pointer assertion

<kaz> wot-thing-description PR 1058 - Add JSON pointer assertion to definition of body sec location

<kaz> 5.3.3.1 SecurityScheme

McCool: Any comments?

Cristiano: This is a good solution.

Cristiano: Can you add "type": "object"?

mc adds it to the PR

McCool: Any other comments?

Cristiano: It should be a common practice to use the same place for the key.

McCool: I thought about that. It is a 10% case.

McCool: We have to leave it the way it is for backwards compatibility.

Proofs and Proofs of Chains

McCool: Next big topic for us is probably Proofs and Proofs of Chains.

Philipp: I added a PR for this topic. The security hardware.

<kaz> Issue 166 - Add integrity protection (proof section) to TDs

<kaz> PR 199 - Add crypto hardware survey in /background

Philipp: Should I add a link to references in the Readme or in the table?

McCool: Should be enough to add it in the Readme.

mc adds some comments in the PR.

McCool: I am going replicate the ld-proofs community proposal and add a list of crypto functions available for it.

ld proofs

McCool: YANG defined names for the crypto functions. It would be reasonable to use it.

YANG

mc adds comment to 166

McCool: Anyone else having comments about signing?

No responses

Issue 196 - Consider security issues in Discovery

Issue 196 - Consider security issues in Discovery

McCool is going through the PR he created

PR 113 - Security and Privacy Considerations

<kaz> 7. Security and Privacy Considerations from the preview of the above PR 113

McCool: I think this is a work in progress.

<McCool> https://github.com/w3c/wot-discovery/pull/113

McCool: Any comments?

No comments. mac adds some thoughts as a comment he had while going through it.

McCool: Any other topics?

No answers

<kaz> [adjourned]

Minutes manually created (not a transcript), formatted by scribe.perl version 127 (Wed Dec 30 17:39:58 2020 UTC).