13:02:31 RRSAgent has joined #wot-sec 13:02:31 logging to https://www.w3.org/2022/11/21-wot-sec-irc 13:02:35 Zakim has joined #wot-sec 13:06:14 meeting: WoT Security 13:06:26 present+ Kaz_Ashimura, Michael_McCool,Jan_Romann 13:06:54 scribenick: kaz 13:07:00 McCool has joined #wot-sec 13:07:12 agenda: https://www.w3.org/WoT/IG/wiki/IG_Security_WebConf#21_November_2022 13:07:52 present+ Tomoaki_Mizushima 13:09:50 topic: Minutes 13:10:02 -> https://www.w3.org/2022/10/24-wot-sec-minutes.html Oct-24 13:12:48 approved 13:13:15 topic: Trusted Environment 13:13:46 i/topic:/topic: Architecture Transition Request/ 13:13:49 three PRs: 686, 747, and 781 13:14:09 s/topic: Tr/subtopic: Tr/ 13:14:16 rrsagent, make log public 13:14:20 rrsagent, draft minutes 13:14:20 I have made the request to generate https://www.w3.org/2022/11/21-wot-sec-minutes.html kaz 13:15:48 i|Trusted Env|-> https://github.com/w3c/transitions/issues/474 transitions issue 474 - CR Request for Web of Things (WoT) Architecture 1.1| 13:16:23 i|Trusted Env|mm: got comments on Wide Reviews from Ralph| 13:17:34 mm: how long would it take for an additional review? 13:17:39 kaz: not sure 13:17:46 ... it depends on their availability 13:18:06 ... but we can ask them to review the additional part quickly if the change is limited 13:18:15 q+ 13:19:04 ... from my view point, what we should do is: 13:19:31 ... 1. see whether there is any content added after the wide review conclusion or not 13:19:56 ... 2. if there really is any addition, we need to see if it's really needed 13:20:19 ... 3. if we can remove it, that's fine 13:20:43 ... 4. or if we really need the addition, we need to ask them for an additional review for that part 13:21:03 mm: regarding #1, I've checked the timing 13:21:47 ... the PR on Trusted Environment was really added one month later the wide review conclusion 13:22:27 kaz: which PR? 13:22:38 https://github.com/w3c/wot-architecture/pull/781/files 13:23:20 s/https/-> https/ 13:23:39 s|781/files|781 PR 781 - Define Trusted Environment| 13:24:03 mm: that is just a definition of a term, "Trusted Environment" 13:28:56 kaz: in that case, we need to think about whether we really need this definition or not as #2 13:29:02 s/#2/#2 above/ 13:30:21 mm: don't think we really need this definition 13:31:55 https://github.com/w3c/transitions/issues/474#issuecomment-1320565680 13:33:24 kaz: would suggest you check with Ralph by sending an email about our proposal before responding on the GitHub Issue directly 13:33:31 mm: ok 13:38:31 kaz: also, we should check with Lagally as well first 13:38:34 mm: yeah 13:48:11 topic: Updates to Security and Privacy Guidelines 13:48:56 -> https://w3c.github.io/wot-security/ WoT Security and Privacy Guidelines 13:49:23 mm: public Note was published on 6 Nov 2019 13:49:50 ... we need thorough review 13:50:02 ... updated definitions, references, etc. 13:51:36 ... should remove the reference to the Best Practices 13:52:30 https://github.com/w3c/wot-security-best-practices 13:52:32 kaz: meaning not the "6. References to Existing Security Best Practices" section but the reference to our own WoT Security Best Practices document. Right? 13:52:35 mm: right 13:53:11 -> https://w3c.github.io/wot-security/#references-to-existing-security-best-practices section 6 - References to Existing Security Best Practices 13:53:21 s|https://github.com/w3c/wot-security-best-practices|| 13:53:30 -> https://github.com/w3c/wot-security-best-practices WoT Security Best Practices document 13:53:42 mm: it has not been published yet 13:55:08 ... (goes through the WoT Security and Privacy Guidelines Note) 13:55:29 ... we need to have a plan 13:55:37 ... discussion on testing procedure, etc. 13:56:07 ... my own general feeling is the document has good content 13:56:20 https://github.com/w3c/wot-security/issues/209 13:56:55 s/https/-> https/ 13:57:18 s/209/209 wot-security issue 209 - Update "Security and Privacy Guidelines" prior to 2022 PR transitions 13:57:36 mm: the issue was generated in August 13:57:51 ... didn't have bandwidth to update the Note 13:58:51 ... note that all the normative/necessary information has been included in the normative specs themselves 13:59:46 topic: Testing 14:00:04 mm: what is the situation for the December Testfest? 14:00:11 kaz: preparing for it 14:00:32 ... think we should see the implementation status for WoT Architecture and WoT Profile 14:01:08 ... but for that purpose, we need to sort the assertion table again based on the appearance order rather than the ID name 14:01:17 ... so that people can tell the context easily 14:01:22 [adjourned] 14:01:26 rrsagent, make log public 14:01:30 rrsagent, draft minutes 14:01:30 I have made the request to generate https://www.w3.org/2022/11/21-wot-sec-minutes.html kaz 15:37:55 Zakim has left #wot-sec