W3C

WoT Security

30 August 2021

Attendees

Present
Kaz_Ashimura, Michael_McCool, Philipp_Blum, Tomoaki_Mizushima
Regrets
-
Chair
McCool
Scribe
citrullin

Meeting minutes

Review minutes

<kaz> July-26

McCool: Minutes are reasonable. Any objections publishing them?

No objections

Cleaning up issues and PRs

<kaz> s|https://www.w3.org/WoT/IG/wiki/WG_WoT_Scripting_API_WebConf#30_August_2021|https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#30_August_2021|

Issue 16

<kaz> Issue 16 - Expand Acknowledgements|

<kaz> ("PR needed" label added)

Issue 14

Issue 14 - TD Signatures and Object Security

mc adds comment and assignes Oliver Pfaff.

Issue 13

Issue 13 - Update Secure Local Transport|

mc adds comments to issue 13.

<kaz> FYI, Decentralized Identifiers (DIDs) v1.0 is now a Proposed REC

McCool: Did is a proposal, which is solid and we can use it. Problem is only that not all did methods are secure enough.

Philipp: can't we mention some properties which have to fulfilled in order to be secure enough for our purposes?

McCool: That is a reasonable point. Can you look into the local security topic?

mc adds a comment to the issue.

<kaz> DID implementation report

McCool: Not all implementations support all feature. pointing out the feature needed is a good idea here. The did:key method is, as far as I know, just a simple local implementation which we might be able to use for this purpose.

<McCool> https://w3c-ccg.github.io/did-method-web/

McCool: Let's study this.

Issue 11

<kaz> Issue 11 - Define interpretation of MUST, SHOULD

<kaz> related Issue 5 - Recommended OAuth2 flows

<kaz> mc adds a comment to Issue 5

<kaz> McCool's comment

Issue 9

<kaz> Issue 9|Publish as a Note

McCool: We should focus on key distribution, TD signing and local security. That would be major step forward.

McCool: as a start cleaning up OAuth is good.

McCool: pb, it would be good, if you can do take a look into the did part. So we can describe the problem and some potential solutions.

Philipp: I will take a look into it.

<kaz> [adjourned]

Minutes manually created (not a transcript), formatted by scribe.perl version 131 (Sat Apr 24 15:23:43 2021 UTC).