W3C

– DRAFT –
WoT Security

07 March 2022

Attendees

Present
Jan_Romann, Jiye_Park, Kaz_Ashimura, Michael_McCool, Philipp_Blum
Regrets
-
Chair
McCool
Scribe
citrullin

Meeting minutes

Agenda

<McCool> https://github.com/w3c/wot-thing-description/pull/1382

<McCool> https://github.com/w3c/wot-security-testing-plan

<JKRhb> https://github.com/w3c/wot-thing-description/pull/1419

<McCool> https://github.com/w3c/wot-testing

Minutes

<kaz> Feb-28

McCool: any objections to publish? No objections.

auto value in in field #1419

PR 1419 - Add auto value for the in field of SecuritySchemes

Jan: There are these issues with these security schemes. I re-generated the json file.

Jiye: I reviewed this PR. I would rather mention to have it as header instead of using auto.

McCool: Adding auto doesn't change anything in the protocol itself. It just adds the info to add negotiate on connection, instead of nothing.

McCool: The TD requires a security scheme. And nosec would be inaccurate.

Jiye: I rather suggest to have auto as security scheme

mm adds a comment to the issue.

Jiye: I think basic security should be used on HTTP. We should mention this.

Jan: Discovery also has some issues with the limitations of security schemes.

McCool: I think using the extension is the right way to go.

McCool: We also use string. We should only allow enums. And use an extension mechanism in order to add other security schemes.

McCool: I think we should hold up merging this, for now.

Philipp: Is that for 1.1 or 2.0?

McCool: 1.1

Philipp: Okay, that makes sense. So we can add it for now and have an extensive mechanism for 2.0

McCool: CoAP and MQTT are the protocols which make some problems.

<McCool> https://github.com/w3c/wot-thing-description/pull/1419#issuecomment-1060690052

Security and privacy consideration

<kaz> wot-thing-description PR 1382 - Create Security and Privacy Questionnaire Answers for Ver 1.1 CR Process|

McCool: There are also some attacks on automated systems possible through an UI.

McCool: A segmented network makes sense in the IoT context.

mm adds a comment to the PR #1382

McCool: let me rewrite it. I need to work on it.

https://github.com/w3c/wot-thing-description/pull/1382/files#r820716329

https://github.com/w3c/wot-thing-description/pull/1382#discussion_r820716329

mm adds a comment

https://github.com/w3c/wot-thing-description/pull/1382#issuecomment-1060707837

Testing plan

<kaz> wot-security-testing-plan repo

McCool: I would like to have a link to the current testing plan on the github readme.

<kaz> github.io

<kaz> (github.io has been set up)

Next week

McCool: there will be the PlugFest next week
... so Security call will be cancelled

[adjourned]

Minutes manually created (not a transcript), formatted by scribe.perl version 185 (Thu Dec 2 18:51:55 2021 UTC).