13:03:49 RRSAgent has joined #wot-sec 13:03:49 logging to https://www.w3.org/2021/03/08-wot-sec-irc 13:03:57 Meeting: WoT Security 13:04:20 Mizushima has joined #wot-sec 13:04:32 present+ Kaz_Ashimura, Michael_McCool, Cristiano_Aguzzi, Elena_Reshetova Oliver_Pfaff 13:05:02 elena has joined #wot-sec 13:05:08 scribenick: elena 13:05:28 Agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#8_March_2021 13:06:26 topic 1: meeting minutes from the last call 13:06:36 s/topic 1:/topic:/ 13:06:50 -> https://www.w3.org/2021/02/22-wot-sec-minutes.html Feb-22 13:08:27 present+ Tomoaki_Mizushima 13:08:29 McCool: meeting minutes approved 13:09:31 topic: cancellations 13:10:17 McCool: next week we have a F2F, so maybe we should skip the security calls on mon march 15 and march 22 13:11:21 McCool: next security call is on March 29, but a short one to capture F2F outcomes 13:12:41 topic: agenda for F2F 13:13:44 McCool: currently F2F agenda looks very full and does not have a security session. Does anyone thinks that we should have a security discussion or it is ok not to have it this time? 13:14:27 general consensus is that there has not been enough security changes that would require a separate security session 13:16:07 McCool: instead people should join existing sessions that might touch upon security issues 13:16:46 topic: S&P consideration note update 13:17:21 i|currently|-> https://www.w3.org/WoT/IG/wiki/F2F_meeting,_March_2021#Agenda March vF2F agenda| 13:20:11 McCool: changes that should be done in the note update: aligning the terminology with arch doc, updating docs, lifecycle?? 13:23:31 AR to Elena to check the current status of lifecycle in the arch spec and raise any issues before the F2F if needed 13:24:19 McCool: the default branch for wot-security has been renamed from master to main. Please update your forks appropriately 13:24:27 topic: issues 13:25:10 fist issue - 197 13:25:40 https://github.com/w3c/wot-security/issues/197 13:26:12 McCool enters a comment to point out the existing PR against the arch spec 13:27:51 s/fist issue - 197/subtopic: issue 197/ 13:28:03 i/https/-> https/ 13:28:04 citrullin has joined #wot-sec 13:29:10 s/197/197 Issue 197 - Promoting an approach where every thing is a server is a security nightmare/ 13:30:21 Next issue: https://github.com/w3c/wot-security/issues/166 13:31:11 McCool reviewed the latest comment on that issue 13:31:40 next issue: https://github.com/w3c/wot-security/issues/196 13:32:08 McCool suggests to review the JSON path draft and puts a comment about it in the issue 13:33:48 next issue: https://github.com/w3c/wot-security/issues/194 13:33:55 McCool: have we ever addressed this? 13:34:11 i/Next issue/subtopic: issue 166/ 13:34:33 i/196/subtopic: issue 196/ 13:34:45 i/194/subtopic: issue 194/ 13:35:05 s/Next issue: /-> / 13:35:32 Cristiano would try to find the good place to have these recommendations added 13:35:52 s/166/166 Issue 166 - Add integrity protection (proof section) to TDs/ 13:36:10 s/next issue: /-> /g 13:36:30 McCool it indeed fits the Best Practices document better, but is the best practices even published? 13:37:59 McCool adding a note that we should formally publish the best practices document 13:38:54 s/196/196 Issue 196 - Consider security issues in Discovery/ 13:38:58 McCool creates a new issue under best practices to add oauth2 recommendations 13:39:47 s/194/194 Issue 194 - Provide guidance on use of OAuth 2 flows/ 13:39:53 rrsagent, make log paper 13:40:04 https://github.com/w3c/wot-security-best-practices/issues/5 13:40:05 s/rrsagent, make log paper// 13:40:08 rrsagent, make log public 13:40:13 rrsagent, draft minutes 13:40:13 I have made the request to generate https://www.w3.org/2021/03/08-wot-sec-minutes.html kaz 13:40:24 McCool: we should aim to publish the best practices as a note 13:42:03 adding a note to issue https://github.com/w3c/wot-security-best-practices/issues/7 13:43:12 Chair: McCool 13:44:06 topic: other ongoing activities 13:44:59 present+ Philipp_Blum 13:45:18 -> https://github.com/w3c/wot-thing-description/pull/1058 wot-thing-description PR 1058 13:45:48 s/PR 1058/PR 1058 - WIP: Add JSON pointer assertion to definition of body sec location/ 13:46:21 McCool puts some comments on this PR 13:48:25 McCool we will be likely to discuss this in TD call further 13:54:40 rrsagent, draft minutes 13:54:40 I have made the request to generate https://www.w3.org/2021/03/08-wot-sec-minutes.html kaz 14:01:45 -> https://github.com/w3c/wot-thing-description/pull/1058#issuecomment-792772332 MvCool's comment 1 to PR 1058 14:02:06 -> https://github.com/w3c/wot-thing-description/pull/1058#issuecomment-792775065 McCool's comment 2 to PR 1058 14:02:09 [adjourned] 14:02:19 rrsagent, draft minutes 14:02:19 I have made the request to generate https://www.w3.org/2021/03/08-wot-sec-minutes.html kaz 16:09:29 Zakim has left #wot-sec