13:04:59 RRSAgent has joined #wot-sec 13:04:59 logging to https://www.w3.org/2022/03/07-wot-sec-irc 13:05:09 meeting: WoT Security 13:05:11 topic: Minutes 13:05:27 -> https://www.w3.org/2022/02/28-wot-sec-minutes.html Feb-28 13:05:36 https://github.com/w3c/wot-thing-description/pull/1382 13:05:47 https://github.com/w3c/wot-security-testing-plan 13:06:09 s|-> https://www.w3.org/2022/02/28-wot-sec-minutes.html Feb-28|| 13:06:13 s/topic: Minutes// 13:06:21 i|1382|topic: Agenda| 13:06:21 https://github.com/w3c/wot-thing-description/pull/1419 13:06:29 topic: Minutes 13:06:31 -> https://www.w3.org/2022/02/28-wot-sec-minutes.html Feb-28 13:06:49 i/meeting:/scribenick: citrullin/ 13:07:34 present+ Kaz_Ashimura, Michael_McCool, Jan_Romann, Jiye_Park, Philipp_Blum 13:07:37 https://github.com/w3c/wot-testing 13:07:57 mm: any objections to publish? No objections. 13:08:08 i/any/scribenick: citrullin/ 13:08:47 topic: auto value in in field #1419 13:08:52 -> https://github.com/w3c/wot-thing-description/pull/1419 13:09:21 jr: There are these issues with these security schemes. I re-generated the json file. 13:10:28 s/1419/1419 Issue 1419 - Add auto value for the in field of SecuritySchemes/ 13:10:32 jp: I reviewed this PR. I would rather mention to have it as header instead of using auto. 13:11:52 mm: Adding auto doesn't change anything in the protocol itself. It just adds the info to add negotiate on connection, instead of nothing. 13:13:26 mm: The TD requires a security scheme. And nosec would be inaccurate. 13:15:31 jr: I rather suggest to have auto as security scheme 13:15:49 s/jr:/jp:/ 13:16:21 mm adds a comment to the issue. 13:18:00 q+ 13:19:43 jp: I think basic security should be used on HTTP. We should mention this. 13:21:21 jr: Discovery also has some issues with the limitations of security schemes. 13:21:36 mm: I think using the extension is the right way to go. 13:23:37 mm: We also use string. We should only allow enums. And use an extension mechanism in order to add other security schemes. 13:24:43 mm: I think we should hold up merging this, for now. 13:26:03 pb: Is that for 1.1 or 2.0? 13:26:16 mm: 1.1 13:26:36 pb: Okay, that makes sense. So we can add it for now and have an extensive mechanism for 2.0 13:27:18 mm: CoAP and MQTT are the protocols which make some problems. 13:31:00 https://github.com/w3c/wot-thing-description/pull/1419#issuecomment-1060690052 13:31:21 q? 13:31:23 ack j 13:31:23 s/https:/-> https:/ 13:31:28 rrsagent, make log public 13:31:32 rrsagent, draft miutes 13:31:32 I'm logging. I don't understand 'draft miutes', kaz. Try /msg RRSAgent help 13:31:41 s/rrsagent, draft miutes// 13:31:44 rrsagent, draft minutes 13:31:44 I have made the request to generate https://www.w3.org/2022/03/07-wot-sec-minutes.html kaz 13:32:16 rrsagent, make log public 13:32:18 rrsagent, draft minutes 13:32:18 I have made the request to generate https://www.w3.org/2022/03/07-wot-sec-minutes.html kaz 13:32:47 topic: Security and privacy consideration 13:32:58 s/Issue 1419/PR 1419/ 13:34:35 -> https://github.com/w3c/wot-thing-description/pull/1382 wot-thing-description PR 1382 - Create Security and Privacy Questionnaire Answers for Ver 1.1 CR Process| 13:34:40 rrsagent, draft minutes 13:34:40 I have made the request to generate https://www.w3.org/2022/03/07-wot-sec-minutes.html kaz 13:36:48 mm: There are also some attacks on automated systems possible through an UI. 13:40:53 mm: A segmented network makes sense in the IoT context. 13:44:59 mm adds a comment to the PR #1282 13:45:38 mm: let me rewrite it. I need to work on it. 13:46:24 -> https://github.com/w3c/wot-thing-description/pull/1382/files#r820716329 13:48:13 s/1282/1382/ 13:49:14 -> https://github.com/w3c/wot-thing-description/pull/1382#discussion_r820716329 13:50:08 mm adds a comment 13:50:09 -> https://github.com/w3c/wot-thing-description/pull/1382#issuecomment-1060707837 13:50:26 topic: Testing plan 13:52:09 mm: I would like to have a link to the current testing plan on the github readme. 13:55:18 i|I would|-> https://github.com/w3c/wot-security-testing-plan wot-security-testing-plan repo 13:55:44 -> https://w3c.github.io/wot-security-testing-plan/ github.ko 13:55:47 s/ko/io/ 13:59:17 (github.io has been set up) 13:59:24 topic: Next week 13:59:39 mm: there will be the PlugFest next week 13:59:47 ... so Security call will be cancelled 13:59:52 [adjourned] 13:59:56 rrsagent, draft minutes 13:59:56 I have made the request to generate https://www.w3.org/2022/03/07-wot-sec-minutes.html kaz 14:00:10 i/github.io/sribenick: kaz/ 14:00:11 rrsagent, draft minutes 14:00:11 I have made the request to generate https://www.w3.org/2022/03/07-wot-sec-minutes.html kaz 14:45:28 zkis has joined #wot-sec 14:52:07 sebastiankaebisch has joined #wot-sec 15:03:40 JKRhb has joined #wot-sec 16:00:26 Zakim has left #wot-sec 16:18:28 zkis has joined #wot-sec 16:23:59 zkis_ has joined #wot-sec