12:04:05 RRSAgent has joined #wot-sec 12:04:05 logging to https://www.w3.org/2021/05/24-wot-sec-irc 12:04:51 citrullin has joined #wot-sec 12:04:54 Meeting: WoT Security 12:05:35 present+ Kaz_Ashimura, Michael_McCool, Phlipp_Blum 12:07:30 Mizushima has joined #wot-sec 12:09:21 topic: Minutes 12:09:30 -> https://www.w3.org/2021/05/17-wot-sec-minutes.html May-17 12:09:32 accepted 12:10:17 Agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#24_May_2021 12:10:25 present+ Tomoaki_Mizushima 12:13:41 topic: WoT Security Best Practices 12:14:00 -> https://github.com/w3c/wot-security-best-practices/issues/9 wot-security-best-practices Issue 9 - Publish as a Note 12:14:18 kaz: we've never published the document as an official group Note 12:15:28 mm: for the consistency with the GitHub repo's name, we should use "wot-security-best-practices" as the shortname 12:16:01 pb: makes sense 12:16:13 kaz: right 12:16:55 -> https://github.com/w3c/wot-security-best-practices/issues/9#issuecomment-847003073 McCool adds comments on the Isue 9 12:17:00 s/Isue/Issue/ 12:18:09 rrsagent, make log public 12:18:14 rrsagent, draft minutes 12:18:14 I have made the request to generate https://www.w3.org/2021/05/24-wot-sec-minutes.html kaz 12:19:52 mm: adds "Call for Resolution to publish update" for Security and Privacy within the June vF2F agenda 12:20:53 -> https://www.w3.org/WoT/IG/wiki/F2F_meeting,_June_2021#Proposed_Topics Proposed Topics section of the vF2F wiki 12:22:55 -> https://github.com/w3c/wot-security-best-practices/issues/9#issuecomment-847006107 another comment on the planning to the Issue 9 12:24:29 mm: we need to do some general clean up for the draft 12:24:44 -> https://w3c.github.io/wot-security-best-practices/ wot-security-best-practices ED 12:30:15 mm: (creates a new issue on secure transport) 12:33:49 -> https://github.com/w3c/wot-security-best-practices/issues/13 wot-security-best-practices Issue 13 - Update Security Transport 12:34:32 mm: need to talk with Ben about what best practice makes sense here 12:36:20 ... we basically recommend OAuth2 flow 12:37:36 ... (adds some more comments to Issue 5 as well) 12:37:57 -> https://github.com/w3c/wot-security-best-practices/issues/5 wot-security-best-practices Issue 5 - Recommended OAuth2 flows 12:38:54 mm: Section 2.1 of the Best Practices document describes the OAuth2 Flows 12:39:06 -> https://w3c.github.io/wot-security-best-practices/#oauth-flows 2.1 OAuth2 Flows 12:40:59 mm: (creates another Issue on TD Signatures) 12:41:18 -> https://github.com/w3c/wot-security-best-practices/issues/13 wot-security-best-practices Issue 14 - TD Signatures 12:46:29 mm: in general, the "object security" section is troublesome since we have no direct experience implementing a system with it 12:47:06 ... so maybe we should just remove this section for now... 12:47:30 -> https://w3c.github.io/wot-security-best-practices/#object-security 4. Object Security 12:48:29 kaz: we can leave it as is and add an Editor's Note for the publication of the group Note 12:48:32 mm: yeah 12:49:28 pb: (also like that idea) 12:50:11 mm: regarding the section "5. Secure Update and Post Manufacturing Provisioning" 12:50:37 s/"5. Secure Update and Post Manufacturing Provisioning/7. Summary/ 12:50:48 ... currently it's empty 12:51:34 -> https://github.com/w3c/wot-security-best-practices/issues/15 wot-security-best-practices Issue 15 - Add or Remove Summary Section 12:51:57 mm: and should expand the Acknowledgements section 12:52:32 -> https://github.com/w3c/wot-security-best-practices/issues/15 wot-security-best-practices Issue 16 - Expand Acknowledgements 12:52:44 mm: we're not ready for publishing the document yet 12:53:30 ... need more improvement 12:53:46 ... (adds some more comments to Issue 5 again) 12:54:24 -> https://github.com/w3c/wot-security-best-practices/issues/16 McCool's new comments for Issue 5 12:54:58 mm: Move the current OAuth2 review into an appendix 12:54:58 ... Pull out the pseudo-RFC2119 recommendations into the main body and reword as necessary... 12:55:44 ... (and then make the "call for resolution" for security during vF2F to "initial call for resolution") 12:56:30 -> https://www.w3.org/WoT/IG/wiki/F2F_meeting,_June_2021#Proposed_Topics Security and Privacy topics within the Proposed Topics section on the vF2F wiki 12:58:26 mm: would like to see what the acceptable practices for secure transport 12:58:30 [adjourned] 12:58:36 rrsagent, draft minutes 12:58:36 I have made the request to generate https://www.w3.org/2021/05/24-wot-sec-minutes.html kaz 12:59:07 Chair: McCool 12:59:08 rrsagent, draft minutes 12:59:08 I have made the request to generate https://www.w3.org/2021/05/24-wot-sec-minutes.html kaz 14:39:17 Zakim has left #wot-sec