12:02:21 RRSAgent has joined #wot-sec 12:02:21 logging to https://www.w3.org/2021/04/19-wot-sec-irc 12:02:28 meeting: WoT Security 12:02:51 present+ Kaz_Ashimura, Michael_McCool, Philipp_Blum, Zoltan_Kis 12:03:31 https://github.com/w3c/wot-scripting-api/issues/315 12:03:49 https://github.com/w3c/wot-scripting-api/issues/314 12:08:49 present+ Tomoaki_Mizushima 12:09:22 Zakim, who is here? 12:09:22 Present: Kaz_Ashimura, Michael_McCool, Philipp_Blum, Zoltan_Kis, Tomoaki_Mizushima 12:09:25 On IRC I see RRSAgent, Zakim, Mizushima, citrullin, McCool, zkis, kaz 12:10:07 present- Zoltan_Kis 12:12:43 scribenick: citrullin 12:13:14 topic: Joint call with scripting 12:13:47 mm: We could have a joint call for two hours. But let's take a look into the topics first. 12:14:03 Security TaskForce related issues -> https://github.com/w3c/wot-scripting-api/issues/315 12:14:18 Discovery TaskForce related issues -> https://github.com/w3c/wot-scripting-api/issues/314 12:15:55 mm: I guess we should comment on the issue what we have to deal with. 12:16:53 mm adds a note into the security wiki. Logistics still under discussion. 12:18:19 topic: Cannonicalization and signing 12:18:54 mm: The problem with cannonicalization are default values. 12:19:33 ... the preprocessor may filled in the default values, if they are not given. 12:21:58 ... The solution: Limiting proof. 12:25:38 mm adds a comment to the wiki regarding this issue. 12:27:20 pb: There should be an issue for it, so that we can think about it more in detail. 12:29:08 topic: Object security 12:29:33 Consider how to support object security -> https://github.com/w3c/wot-security/issues/185 12:30:10 mm: .local domain are problematic to secure. 12:31:11 ... there are still information which can get leaked, even if the body is encrypted. Query parameter for example. 12:33:28 pb: We may can use DIDs here and store the related keys etc. attached to the DID in a DLT. 12:33:51 https://tools.ietf.org/html/rfc7165 12:33:53 mm: We don't have experience with that and it probably takes too much time to get this experience. 12:33:55 q+ 12:35:26 Kaz: I agree that we might want to use DID for that. But I agree that it takes too much. 12:37:04 mm: There is a way to distribute keys via DID. But this goes beyond IoT. 12:39:15 pb: Newer versions of HTTP allow encryption of headers. Not sure about queries though. 12:40:05 mm: TLS relies on global domains. And that doesn't work in .local. 12:40:53 ... for now we have to allow http for discovery. 12:43:37 pb: So the might have to say in the best-practices, if you want to have object security you should put the queries into the body. 12:45:43 mm: Problem is that discovery supports queries in the URL and therefore they cannot get encrypted. SparkQL on the other hand allows the queries in the body. 12:46:35 https://krellian.com/ 12:47:48 topic: OAuth2 flows 12:49:22 pb: I think we can remove the submitter etc. 12:49:34 mm: Yes, there are some things which can get simplified and removed. 12:50:27 ... have you made a PR for the use-case document? 12:51:01 pb: No, I haven't. We should talk with Michael Legally first, I think. 12:55:25 oAuth2 flow issue -> https://github.com/w3c/wot-security/issues/194 12:55:43 oAuth 2 flow PR -> https://github.com/w3c/wot-security-best-practices/pull/10 12:56:03 -> https://github.com/w3c/wot-security-best-practices/pull/10 wot-security-best-practices PR 10 - Move oAuth2 flow from usecases to security-best-practices 12:56:19 q+ 12:58:07 ack k 12:58:54 kaz: please note the default branch for the wot-security-best-practices repo has been also rename to "main" 12:59:13 s/oAuth 2/OAuth2/ 12:59:44 i/please/scribenick: kaz/ 12:59:56 [adjourned] 13:00:10 rrsagent, draft minutes 13:00:10 I have made the request to generate https://www.w3.org/2021/04/19-wot-sec-minutes.html kaz 13:00:36 rrsagent, make log public 13:00:37 rrsagent, draft minutes 13:00:37 I have made the request to generate https://www.w3.org/2021/04/19-wot-sec-minutes.html kaz 13:00:55 Chair: McCool 13:00:56 rrsagent, draft minutes 13:00:56 I have made the request to generate https://www.w3.org/2021/04/19-wot-sec-minutes.html kaz