W3C

– DRAFT –
WoT Security

18 July 2022

Attendees

Present
Jan_Romann, Jiye_Park, Kaz_Ashimura, Michael_McCool, Tomoaki_Mizushima
Regrets
-
Chair
McCool
Scribe
kaz

Meeting minutes

Minutes

July-11

approved

New Charter

Jiye: any concrete points last meeting?

McCool: yes, recorded within the minutes and the GitHub issue

Issue 978 - Goals and Deliverable Discussion for WoT WG 2023 Proposed Charter

TD Issue

Issue 1497

TD Issue 1497 - Identifiers don't seem to rotate enough

McCool: no response fro @jyasskin yet
… nothing for Discovery or Architecture
… should I ping the reviewers?

Kaz: yes, please
… you can ping them by email as well

McCool: (shows the issues on the privacy-request repo)

w3cping/privacy-request/issues

McCool: original issues have been
… but we still got additional comments
… and need their responses
… let's wait for one more week

original issues

TAG Feedback

<kaz> s/topic: TD Issue 1497/topic: Wide Review/

w3ctag/design-reviews Issue 736 - Web of Things (WoT) Architecture 1.1

McCool: response from the WoT Security TF
… security best practices document was meant to containg a set of non-normative statements

(some more discussion)

McCool: (clarifies actions as well)
… remove references to "Security Best Practices" in normative documents
… review and update prior to PR transition of other deliverables
… update references to ensure that all references to "Security and Privacy Guidelines" are informative
… review and update security and privacy assertions so they are testable statements about implementations

Kaz: this is inline with what I've been suggesting, i.e., clarifying the relationship between the Security Notes and the other REC-Track deliverables

McCool: ok
… any objections from others?

(none)

McCool: (commits the comments)

McCool's comments

McCool: (skims Editor's Drafts)

WoT Architecture 1.1

WoT Thing Description 1.1

WoT Discovery

McCool: (updates his comments)

updated comments

AOB

McCool: (updates the agenda for the next call

mizu: note that we'll have the Testfest next week

McCool: good point
… Security TF call canceled due to the Testfest on July 25
… please review the TAG Issue

TAG Issue 736

McCool: and specifically consider how to modify security/privacy assertions in the WoT deliverables to make them more testable

[adjourned]

Minutes manually created (not a transcript), formatted by scribe.perl version 192 (Tue Jun 28 16:55:30 2022 UTC).