12:59:45 RRSAgent has joined #wot-sec 12:59:45 logging to https://www.w3.org/2021/11/22-wot-sec-irc 13:02:04 meeting: WoT Security 13:02:13 present+ Kaz_Ashimura, Jiye_Park 13:05:07 present+ Michael_McCool, Philipp_Blum, Tomoaki_Mizushima 13:06:38 rrsagent, make log public 13:06:45 rrsagent, draft minutes 13:06:45 I have made the request to generate https://www.w3.org/2021/11/22-wot-sec-minutes.html kaz 13:07:14 chair: McCool 13:08:16 citrullin has joined #wot-sec 13:08:53 scribenick: citrullin 13:09:41 topic: Minutes review 13:10:04 Jiye has joined #wot-sec 13:11:14 McCool has joined #wot-sec 13:11:16 https://www.w3.org/2021/11/15-wot-sec-minutes.html 13:13:10 mm: I looked into several IETF documents. 13:13:31 ...having some thoughts how to proceed with it. 13:13:41 mm: Anyone having objections? 13:13:44 no objections. 13:15:32 topic: Local transport and secure onboarding 13:15:44 -> https://github.com/w3c/wot-security-best-practices/pull/28 13:16:40 mm: I read the IETF specification and added a PR for the security-best-practices accordingly. 13:18:07 mm: Problem is that TLS 1.3 has been released, but DTLS 1.3 hasn't been released yet. 13:21:36 jp: For TLS1.3 this privacy expose risk is not happening? 13:21:49 mm: I don't know if that is a problem in TLS1.3. 13:24:34 mm: Offline and local networks are different. Local networks only have a NAT, while offline networks don't have a connection to the Internet at all. We should split that up in different sections. 13:24:49 rrsagent, draft minutes 13:24:49 I have made the request to generate https://www.w3.org/2021/11/22-wot-sec-minutes.html kaz 13:30:05 https://datatracker.ietf.org/doc/html/draft-ietf-ace-oauth-authz 13:32:29 s/http/-> http/ 13:41:04 jp: I wanted to talk about the onboarding stuff. 13:42:02 mm added a comment to PR #28 13:42:11 -> https://github.com/w3c/wot-security-best-practices/pull/28#issuecomment-975534690 13:42:49 mm: I think the terminology is confusing. 13:43:25 jp: I agree. What is the onboarding, config, certificates? We should clarify the context. 13:44:44 mm: The context should be WoT. We can assume that the certificates situation is solved. 13:45:32 jp: In order to setup the device we may want to use a mobile phone. 13:48:09 mm: We have a life-cycle section. It is a bit contradicting and too short anyways. 13:48:37 s/life-cycle/lifecycle section in the architecture/ 13:49:43 mm: We have the problem that the term "onboarding" is used for a lot of things in the industry. 13:51:20 mm: There is also a discussion about group keys. 13:52:31 mm: In general groups keys are problematic and have holes in them. They are also difficult to update. 13:53:40 mm adds a comment to #28 13:53:41 -> https://github.com/w3c/wot-security-best-practices/pull/28#issuecomment-975547662 13:54:31 mm: I need to re-read the specification. I am going to add all the references when I find them to the comments. 13:55:56 action: Separate local and offline sections. 13:56:08 action: deal with TLS1.3 and DTLS1.3 13:57:28 action: finish reading DID, VC, SZTP, BRSKI, Authz, EST 13:59:59 action: Also should look at MUDs to document trust relationships 14:01:17 [adjourned] 14:01:20 rrsagent, draft minutes 14:01:20 I have made the request to generate https://www.w3.org/2021/11/22-wot-sec-minutes.html kaz 15:31:49 Zakim has left #wot-sec 15:41:22 Mizushima has left #wot-sec