13:06:07 RRSAgent has joined #wot-sec 13:06:07 logging to https://www.w3.org/2022/02/21-wot-sec-irc 13:06:15 meeting: WoT Security 13:06:43 present+ Kaz_Ashimura, Michael_McCool Jan_Romann, Philipp_Blum, Tomoaki_Mizushima 13:06:47 topic: Review minutes 13:06:49 chair: McCool 13:06:56 scribenick: citrullin 13:07:29 agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#21_February_2022 13:08:14 -> https://www.w3.org/2022/02/14-wot-sec-minutes.html Feb-14 13:09:21 mm: any objections? No objections. 13:11:32 topic: restructuring lifecycle section 13:11:51 Issue 704 -> https://github.com/w3c/wot-architecture/pull/704 13:12:27 mm: There is a confusion about bootstraping. It may include key distribution. I need to look into this again. 13:14:49 topic: name and in fields 13:15:05 issue 1394 -> https://github.com/w3c/wot-thing-description/issues/1394 13:15:26 mm: If it goes against the spec, we have to fix this, even if it breaks the spec. 13:15:51 jr: I am not sure, if that is such a critical issue. 13:18:49 jr: The basic scheme could also be used with MQTT, but this isn't allowed from the spec. 13:19:01 mm: The Scheme tried to be as generic as possible. 13:20:09 jr: I think the security scheme should be revisited for TD 2.0. 13:21:47 jr: I think Ege also mentioned some changes in OpenAPI. There is some realignment necessary for TD 2.0. 13:22:37 mm adds a comment to #1394 -> https://github.com/w3c/wot-thing-description/issues/1394#issuecomment-1046876055 13:27:16 jr: In general the problem is that the schemes are all inspired by HTTP. 13:29:34 mm: Jan, can you take care of it and create a PR? 13:29:37 jr: Sure, will do. 13:34:45 mm adds a comment to 1394 -> https://github.com/w3c/wot-thing-description/issues/1394#issuecomment-1046887555 13:35:11 topic: Security and Privacy Considerations 13:35:25 Issue 1402 -> https://github.com/w3c/wot-thing-description/pull/1402 13:35:34 mm: I need someone to review this. 13:38:03 mm: I added the risk of the field title/description. To make it short: Sanitize your strings, just like in HTML. 13:38:56 mm: Add PII in the id or other fields shouldn't be done. I added that as well. 13:44:56 topic: Review Security Questionnaire 13:54:59 -> https://w3ctag.github.io/security-questionnaire/ Security questionnaire 13:55:18 Issue 1382 -> https://github.com/w3c/wot-thing-description/pull/1382 13:55:32 s/Issue 1382 // 13:55:52 mm adds comments to #1382 -> https://github.com/w3c/wot-thing-description/pull/1382#issuecomment-1046904114 13:55:52 s|pull/1382|pull/1382 PR 1382 - Create Security and Privacy Questionnaire Answers for Ver 1.1 CR Process| 14:03:02 [adjourned] 14:03:08 rrsagent, draft minutes 14:03:08 I have made the request to generate https://www.w3.org/2022/02/21-wot-sec-minutes.html kaz 15:02:02 Mizushima has left #wot-sec 15:03:50 rrsagent, make log public 15:03:51 rrsagent, draft minutes 15:03:51 I have made the request to generate https://www.w3.org/2022/02/21-wot-sec-minutes.html kaz 15:33:50 Zakim has left #wot-sec 17:09:35 sebastian has joined #wot-sec 17:44:11 zkis has joined #wot-sec 19:37:32 zkis has joined #wot-sec 20:08:05 zkis has joined #wot-sec 20:12:55 JKRhb has joined #wot-sec 22:14:15 zkis has joined #wot-sec 22:32:21 zkis has joined #wot-sec