W3C

– DRAFT –
Decentralized Identifier Working Group

30 July 2026

Attendees

Present
JennieM, ottomorac, pdl-asu, swcurran, TallTed, Wip
Regrets
-
Chair
ottomorac
Scribe
transcriber-bot

Meeting minutes

<ottomorac> transcriber-bot, connect

Agenda Review, Introductions

Otto Mora: Uh, okay...
… So
… Uh, yeah, today we are, uh, just having a conversation, a brief conversation about the TPAC session
… Scheduling the status of the CR transition request for debt resolution
… Uh, and then, uh, we have a DID resolution threat model discussion, which would be kindly facilitated by Steve McCown
… Then we'll try to take a look at the did URL dereferencing PR from Joe and the status of that
… And if time permits, we may get to some
… Uh, data resolution issue processing. Uh, so, we'll see, we'll see if time permits, but is there anything else that folks want to add?

TPAC Session Schedulling

<ottomorac> w3c/tpac2026-meetings#64 (comment)

Otto Mora: Not hearing any any additions. Okay. So on the Tpac session scheduling. Uh, this is the… Uh, conversation thread related to that, and uh… Uh, yeah, I think, uh
… We had a a bit of a mix up there on the the dates that
… We we requested like and so like Will has tried to. Get that sorted out. And, uh
… Yeah, he's, like, uh, basically Ian came back to us saying that, uh, he can offer to move to meeting Tuesday, but there's only 3 slots on Tuesday, and
… Would we like to reduce the meeting to 3 slots on Tuesday, or have those 3 slots, plus a fourth one on another day? So, what day?
… I see Will has his hand up. So yeah, go ahead, Will

Will Abramson: Yeah, exactly. I mean, I think the question is really to the guru as to...
… you know, what do we want to do? Do we want to just have three thoughts? My sense is
… if we were gonna have 3 slots and a slot on the other day, like, I'm kind of tempted to ask for 5 slots, right? So we have maybe 3 slots and then 2 slots, because 1 slot just feels like
… Not enough to do useful things, but I'm interested to hear what other folks think

Otto Mora: Within Zoom, I see that, man. Let's restart. Go ahead, man...

Manu Sporny: Sorry, I just, uh, went from, um...
… Have we… so there is going to be a payments, um, meeting Tuesday afternoon, uh, that I think is going to be of big interest to folks
… in the group. Um, have we talked with Pierre-Antoine yet about the DID methods? Charter, um
… Like, is that part of what we're talking about here, or… because there's, in theory, going to be discussion around the DID Methods Working Group Charter, hopefully, on one of the days. That could be one of the slots, and then we could talk about, you know
… the DID core stuff and resolution on another day. Um, we also should figure out how many people from the working group are going to attend, right? Because if we don't have enough turnout, then there's no need to meet. But I think a decent chunk of us are
… you know, gonna be there. Uh, so, um, have y'all, uh, discussed those items, uh, Will, Otto?

Will Abramson: Uh...

Otto Mora: Sure. I think Will's best positioned...

Will Abramson: Yeah, well, the problem is, I haven't really spoke to PA for a while. He's been away, and he's away this week. Uh, I haven't… yeah, so I haven't talked to him about, uh, really any of this, other than just flagging this issue to him...
… Uh, I… I don't know what the status of the methods
… chapter is. But yeah, I think my… my, like, loose expectation was that some of this working group time would be spent on
… on… well, really on figuring out what's… what's next, and maybe that partly is the DID Working Group… DID Methods Charter, but, you know, also, I think it might be
… what do we want to do as a group next, right? Like, if we're not… you know, our charter expires
… So, either we're going to be done, which is great, I would love that, but if we're not done, we're going to need to think about what we want to do, so… Yeah

Otto Mora: Manu?...

Manu Sporny: So typically what happens to groups these days at W3C when they're done is they go into maintenance mode. That was my expectation. And when they go into maintenance mode, typically the charter says we will continue to maintain the specifications. So minor versions of the specs can be published...

Will Abramson: Hmm...

Manu Sporny: Um, and usually it says, for any unfinished work, we will finish that work and take it through the rest of the process. Um...
… That was my understanding of what would happen. I don't think we need to
… Anyway, that was my expectation. I didn't think we were just going to stop the group. That would be not a good thing, obviously. And, you know, we need to free up time to
… work on DID methods, it needs to be done, right? And so, we can't, you know, taking on new work
… Uh, I don't think is, uh, necessarily a good thing for this, uh, group to do. So, I think we should… and TPAC's not the time to have that discussion, right? I mean, the time to have the discussion is now, because it takes months to prep the
… Maintenance charter and all that kind of stuff, like if we're having this discussion at TPAC, that's not a, we're not in a good position. So, um, my presumption was that PA had already started kind of that discussion. The second we go into CR, that's when that discussion

Otto Mora: Definitely...

Manu Sporny: should start, um, because at that point, you know, there's a fairly easy maintenance charter that can be put in place. Um… Anyway, it...

Otto Mora: There was a recharter, though. I think there was a recharter. I think I did see… Over next...

Manu Sporny: There was an extension, which is not a recharge. We got extended for six months, which the W3C management can do without consultation with the membership. um...
… but after that, they can't extend. They have to go back to the membership, and the membership has to vote on the maintenance, um, charter, uh, which means that they… we have to prep a maintenance charter

Otto Mora: Mm-hmm...

Manu Sporny: for vote and get that vote in before our charter expires, ideally. Um, sometimes they extend because we're still talking about the charter, but since we've already had an extension, that's going to be difficult for management to do. um...

Otto Mora: Yep. Mm-hmm...

Manu Sporny: I suggest the chairs have that discussion with PA. It sounds like we've got some process things that are… Dragging out that...

Otto Mora: Yeah...

Manu Sporny: we need to address...

Otto Mora: Yeah. Um, Will, did you have anything else to add?...

Will Abramson: Yeah, I mean, I think that all sounds… like, yeah, we definitely need to get some time on task with TA, he's just been out for the summer, I guess. I think something came up this week, he also had to be around, but then he, um, messaged us and said he can't be available, and obviously now I'm away for two weeks...
… after this. So, yeah, things ticking along. Uh, I… I didn't realize that thing about the maintenance charge. I think that's great. I'm sure PA has it, you know, in his size. Uh, but yeah, we can definitely follow up on that. I mean, I… just to get back to the question at hand here, like. I mean, I'm happy for us to have some time to talk

about the data methods chart, or whatever, that makes sense. Like, I'm also… I think I agree, like
… I want this working group's work to be done. I don't think I'm suggesting that we're going to be considering taking on new features or whatever. Um
… So, makes sense. All sounds fine. Uh, I guess, really, the question is, you know, how many sessions at TFACS do we want to have, right? Is 3 enough, or is 3… I mean, I hear you saying, like, payments is maybe something that we should be aware of, so maybe we should just have 2 on Tuesday, and then try and get 2 a different day
… I mean, unfortunately, because we messed up the scheduling, it just means it depends what available space there is for us to use

Otto Mora: Yes...
… Okay, well
… To be continued, I guess, yeah, like, I guess let's just first circle back with Pierre and… And then try to push it out more
… Um, okay. So, uh, second topic

Will Abramson: Yeah, that's awesome...

Otto Mora: But yeah, so go ahead. Yeah...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): If you may, before we roll on...
… Um, we're clearly running into an issue with PA's availability, and this has been a similar thing that's happened in other groups when the staff contact is
… Unavailable for whatever reason
… I think we need to push
… Push W3M to, uh, W3 management to adjust that piece of things such that there is a backup staff contact

Otto Mora: Mm-hmm...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): Or secondary, or just a second, a co-contact, or situations like this...
… Because we're really under a time limit that we can't fix, and PA's availability is going to impact what we can do, or the results of what we need to do. Oh. I'll leave it at that

Otto Mora: No, no, that's completely valid. I, for instance, like for my discussion around the transcriber bot, I just reached out to Ivan on...
… on Signal, because that's the only option I had, but I think, yeah, it's worth, uh… worth seeing if somebody… especially because I did hear he's going to be out for a few… a few weeks more in August, so… so yeah, that makes sense
… Okay
… Um, so would Ivan be the right person, Madam, for me to just ask, or
… Maybe someone else?

Manu Sporny: Um...

Otto Mora: Oh. Okay. Yes...
… Mmhm

Manu Sporny: Yvonne's technically retired and not in safety. So no, like I agree with Ted, W3C is, you know, under resourcing, dids a bit...

Otto Mora: Okay...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): You could probably ping Philippe if you just need somebody else to talk to about this...

Manu Sporny: I agree with Ted, what he said...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): Um, there are others, but...

Manu Sporny: I think we need. Yep. PLH...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): Yeah. Anybody that you have contact with who's a member of...
… W3 staff would be fine to have this conversation with to start with, and then it's going to roll on and involve others. But it needs to get started before PA is back available

Otto Mora: Yeah...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): Uh, asking Yvonne who might be a good person to talk to, that I think would be valid. Asking him to jump into it, not so much...

Otto Mora: Right. Right. Oh, yeah. That that's exactly. Yeah. Yeah. That's what that's what my thought was. Like, who would be the not not not have and do it, but, like, who would be the yeah. Okay. Cool. I'll I'...
… Right

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): Yeah, and I would make it clear to him that that's what you're doing, because he will… he is the type of person who will try and grab the horse by the reins, uh, just because it needs to be done...

Otto Mora: Bless his heart. Yeah. Yeah. Bye...

CR Transition Request Review

Otto Mora: Um, alright. Perfect. Thank you. Alright, uh

<ottomorac> w3c/transitions#823

Otto Mora: The next topic, just more of a brief status update on this CR transition request, which is here
… Um, so on this one, uh, just like quickly hearing that, uh, like Manu's already aware of this, but just also for the rest of the group, we, um
… We did file the transition request. We did get a reaction from PLH Philippe Le Hackeret, and he then pointed out that we have one issue for TAG
… This one, which is from the design review, uh, group, that is, uh, pending, and that me and Will have been following up on, and uh
… We have like gotten a response from Lola saying that she's taking. They only took a look at the 1st section, and that they're gonna bring this back and then finish up the review, and then we'll kind of responded, adding some additional detail. Uh, but as I understand it

Manu Sporny: Ted's on the queue before me...

Otto Mora: we shouldn't be at risk from from this. And yeah, that's that's kind of the the latest on that. So just to just update the group. I don't know if anybody has any reactions or comments they want to add, or yeah, go ahead, man. Oh, sorry, was this from before, Ted, or...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): Oh, yeah, that's… that's...

Otto Mora: Alright...

Manu Sporny: Okay. Got it. Um...

TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com): I've already spoken...

<Wip> w3ctag/design-reviews#1157

<ottomorac> w3ctag/design-reviews#1157

Manu Sporny: I'm I'm I'm, like, trying to find Lola's response. Do you have a link to it that we can put in the minutes?...

Otto Mora: Oh, yeah, yeah, sorry, here. inspection...

Manu Sporny: Okay, um… that is very unfortunate that they're responding in the way that they are right now. They said they're gonna have something for us by next week, and the unfortunate thing there is, what are they reviewing? for the second part of the spec. Uh… no...
… we need to give them something specific for them to review, or they're in danger of reviewing the wrong thing and giving us a bunch of feedback that is not relevant, which will make them annoyed, and it will make us annoyed and slow us down. And if they raise a bunch of issues

Otto Mora: Mm-hmm...

Manu Sporny: then there's an open question on whether or not we have to resolve those issues now before we go into CR, right? This is highly not good for them to respond in this way after not saying anything for a super long time, so… Umm...
… We can ask them if
… When they give us the feedback, we can do a quick, like, we will take care of those in CR, are you okay with that?

Will Abramson: Okay...

Manu Sporny: so that we can transition into CR. Otherwise, we run the risk of, like, okay, they opened 15 new issues, and now we have to process all 15 before we go into CR, and that'll not be a good outcome. So, maybe point them at… um...
… Joe's PR and say, this is the direction we're taking with did URL dereferencing, please take a look at it. Uh, it is rough, but it's the direction the group's taking, and then… um… We go into CR with that

Otto Mora: Thank you. Uh, Will?...

Will Abramson: Yeah, uh, I mean, I… it's kind of frustrating they haven't responded to me, uh, because I kind of was trying to get at that, like, you know, please don't review, did your LD referencing, because there's no, you know, you're just gonna waste your time, is kind of what I'm hinting at. I mean, I could drop a link to the...
… PR and say that, but, like, in some… and I definitely agree, I'm hoping that any issues that they raise now, they will be happy for us to address them in PR, especially given how long it's taken them, you know, like, to get back to us on this. You know, like, uh, I don't know, a couple of months ago, they asked on the status
… of, like, how we're doing, right? And I replied with a very long and in-depth list of all of their issues that Jeffrey had raised, and how we've addressed them, and then didn't hear anything back from them. For a long time, and
… and tried to ping them again, so, you know, like, we want to go to CR, like, what's the status on this, so, like
… I feel like they have been unresponsive, and it would be, I agree, very, very frustrating if they came back to us and said, uh
… you know, there's all these issues, and you need to address them before you go into CR. That's not really acceptable

Otto Mora: Mm-hmm. Yep. Better...
… Okay

Manu Sporny: Yeah. And unfortunately, this is where the staff contact jumps in and does the negotiation and talks. So we need PA, like right now, and PLH has said, basically said, I'm not going to look at this again until they time out. And now it's not clear what timeout means...

Will Abramson: Mm...

Manu Sporny: Because they did time out and now they're not, you know, they said, give us another week. It's been a week. What's timeout?...
… in this… this is a weird situation we're in, like, that's why they should not have responded in the way that they are. Um… uh, we can let them know that, hey, we're blocked going into CR. Well
… Based on your feedback, they can respond back with, like, we don't care, right?
… Uh, here's our feedback, you know, here's 15 issues. Um
… So, you know, the question to PA and PLH is, what… define timeout
… They timed out before. They've given us feedback. We responded to them. They timed out telling us whether or not it worked. Now they're saying they're going to, you know, review the second part of the spec. What does timeout mean? I think would be the way to move this forward without PA. Um

Otto Mora: Mm-hmm...
… Uh, yes, Will

Manu Sporny: And, you know, make it clear that we're perfectly happy to respond to their feedback, but… You know...

Will Abramson: Yep...

Otto Mora: Let's please...

Manu Sporny: We need to move into CR...

Otto Mora: During the NCR, yeah. Well...

Will Abramson: Yeah, so, I mean, yeah, Pierre's not going to be back until next week, maybe I'll talk to him next week, but I will take a task to reply to this CR transition request with, kind of, what you're saying, and where we're at, and what we're thinking about this...

Otto Mora: Okay...

Will Abramson: Yeah, on this thread, I'll reply. Um, we can see what they say. And maybe I'll also ping on the design review thread and say, you know, it's been a week, we're really...

Otto Mora: Mm-hmm...
… Yes

Will Abramson: wait, and I'll… yeah. So I'll do that before I go away, um, but then I'll tell you all to chase up here, and there's a whole laundry list of things that we need him for. I think he's going back for a week, right? And then he's also going to be away again, so hopefully in a week he can give us a lot of his time. Attention...

Otto Mora: Yeah, next week he's just, uh, Monday to Thursday, and then he's gone until the 17th, that's what he said...
… Alright, okay
… Uh, okay, thank you. Okay

DID Resolution Thread Model Discussion

Otto Mora: Okay. So, uh, yeah, so now for the main topic of today, um
… Which was, uh, the resolution threat model discussion. Uh, so today we wanted to just have a follow-up on that, and, uh, Steve McCown was gonna… Kind of walk us through that. Uh, so
… That's, uh… that was the plan, let me see… Uh, yeah, so we want to do some ideation on the threats that are not related to the debt resolution process, and
… And, uh, see if we can get some additional ones and refine a few of them

Steve McCown: Thank you. Let me go ahead and share my screen here...
… Uh, let's see
… Trying to make sure that I get the right screen and not my personal journal or something like that

Otto Mora: I'll let I'll yield the floor to Steve McCann...

Steve McCown: And. All right, how does that look?...

Otto Mora: Yeah, we see the Word doc or the Google doc there, yeah...

Steve McCown: Is that readable? Should I shrink it?...

Otto Mora: Uh, maybe a little larger, I think a little more soon...

Steve McCown: Okay, is this getting better?...

Otto Mora: Yeah, just a bit more. There we go. That's good. That's good. Yeah...

Steve McCown: Okay. All right. Yeah, I can… I can...
… Make it bigger if that would be helpful. Okay, so what we've done, Joe and I, and he's also worked with some others and some other groups on this
… is, um, we've put together a threat model. I'll just kind of walk through it real quick, and I can do it as fast or as slow as you'd like. And then, but I'm open to any questions
… I guess I should jump on IRC so that I can
… I don't see that
… There we go. All right. Sorry about that
… All right
… So what we've done here is we've put together kind of a threat model describing the DID resolution process is where it started, and then we added a few more threats related to DIDs in general
… Um, and so the idea here is that, um
… A threat is just an… basically think of it like an area of concern. It's not necessarily a vulnerability that needs to get patched
… Um, but an area of concern that needs to be addressed. So, the purpose of this document is to describe at a kind of a high level the major components of the DID and DID resolution model
… And then to start talking about some of the potential threats that can happen. So, I won't walk through all of this, but we can make this available for everybody to review offline
… Um, so generally, uh, what we've done is we've put together an architecture
… um, an architecture section that describes the DID process. So over here, we have a client user device

<ottomorac> link: https://docs.google.com/document/d/1Jpc7hKFjJCFEOJ7cIJXRQYeuLymPNgvwbR6T9WpQfiE/edit?tab=t.0#heading=h.w763ex8narzh

Steve McCown: Uh, implementing DIDs, um, they go through a resolution process, and then over here to, um, a VDR for resolution. And like I say, this is not meant to be exhaustive of every component
… but representative of the major components, paying particular attention to the communication steps
… And so we go through in detail what each component means
… what it refers to, and how it fits with others. Then we have an architecture directory that, um, describes all of that in detail, so that when we… when we look at these diagrams up here, and it says P2 and P3. Um, it's clear what, what those all. referred to. Umm. We give down here a couple of examples
… where we start off with the simplest with did key, and we walk through
… Uh, that process and the major elements and, and that. And that process and those diagrams. And then we take one that's a little bit more
… Complicated, which is BTCR2
… Um, using the Bitcoin blockchain, if that presents a
… problem. I know there's been concerns about blockchains in the past. We didn't mean to complicate
… anything by by using that. We just use that as a widely used method process. And so that one
… You can see that it got a little more expansive. Talking about the extra components. Umm
… mainly, let me jump down here. This is the part of real interest. So, you all knew all of that, so I don't need to go into that. So, what we've done is we've created a
… a threat model. The idea is to make this simple, because it's not something… it's like software testing. It's not something people really like doing all the time, but it's something that's really, um, important and needs to be done
… And so the general format, and we've outlined it in this Word document, but Joe's written some code where you should be able to populate
… Um, an issue in the GitHub, uh, repository where it pops up with these specific items, uh, pre-filled, and then, um, the submitter can go through and, uh, add
… um, the specific information to this format that gets displayed. Um, so basically, it starts out with… with an ID
… just an ID number of the threat, 1, 2, 3, whatever. Um, and then there's a description of what the threat is, and with threats, there… we just need to… this isn't like providing a patch or a… Um, uh
… code to fix the problem. What it is is saying, there can be a threat, and I'll talk about some in a minute, and then there might be one or several different potential responses that we can use to address that
… So, sometimes you mitigate the risk, sometimes you accept the risk. Umm
… With, you know, a general computing model, one of the potential threats is the power goes out, the computer turns off. Well, there's not a whole lot you can do about that. You might accept that risk as a way of doing business
… You might respond to that by
… periodically saving your document or running a UPS, and so there's various things that you can do in response to that threat of the power going out in that high-level case
… And so we've there's a couple of different taxonomies of threat models. We've particularly used the stride model in our discussion. I won't really go into that, but basically in the stride model
… Um, there's different types of, of, um, threats. Spoofing an identity, tampering with data, uh, repudiation, information disclosure, and denial of service. And so that's something that, uh. We we liked that model. It was very straightforward
… But there's other models as well. And so the threat category, um, refers to one of those I just mentioned. The taxonomy is… is the
… taxonomy of the threat model. And then we start getting into detail, um, and then in… right here it talks about, uh, what elements are affected, and then who submitted that. Um, and so there's various types of threats. Let me just kind of jump down here for the sake of time. Um
… Um, so here's… here's one of the implementation threats that, um, we talked about. Um
… so the DID resolution in the description, it says the DID resolution service provide… providers receive a significant amount of data that may reveal personal or proprietary information. So, using the STRIDE model, we, um, classified this as an information disclosure
… And we have several potential responses that we could take to mitigate that threat. So the first one in item D there, response R1, convey the threat likelihood
… When onboarding users to a particular dead resolution service provider, it's important to communicate the data use policy. So, if data will be collected and used for
… some sort of analytics or anything like that. That needs to be, uh, communicated, and what that does is it kind of… it transfers
… the risk into that response
… So, a couple others are, um… in this one, what we're doing is recommending maybe a local resolution might be better in certain cases
… where a local resolver is run on the requester's infrastructure. And, um… Talk about the difference, about why local versus cloud might be important. Um, and so that's kind of a recommendation, uh, step to accept that risk, and so the user can decide, no, I really want the cloud service, or I really want the local service
… Um, whereas this one right here on G is the local resolution, and we're transferring that risk of the potential threat that was present in the cloud. We're transferring that to the local. That lets the user assume all that risk
… But do so in a way that's maybe, um… more acceptable to them. And that's not to say
… locals better than cloud. They're just different, and they might be more valuable in different scenarios. Umm. Couple others that we we looked at surveillance by proxy so that. There's been discussion of proxying resolvers, where there's kind of a meta resolver that farms the request out to, um
… different other resolvers, so that it just kind of gets relayed, and then the data comes back. Well, that creates some situations where there's more entities that can
… uh, monitor the requests, or, um, and then we walk through, you know, how, how those could be resolved, or are those threats mitigated?
… Um, all the way even to, uh, duty of care or duty of loyalty, uh, which Utah is using in the SETI, which is basically contractual terms of service
… Umm
… And so we walk through a number of these threats. The idea is that what we end up with when we do this, sometimes we might, these might result in modifying the spec through a PR of some sort
… or it might just be result in a best practices implementation guide for users so that they can make decisions of whether they want to subscribe to a cloud resolution service or implement their own. or how they might handle some of these cases as they affect. their particular infrastructure that they're they're building. One of the other threats

was repudiation. So when we get in the case of these proxying resolvers where I say, Hey, Meta resolver, can you resolve this did?
… And it says, okay, let me farm that out to DID resolver number 7
… Um, okay. Is there… a potential for repudiation of of that process? And does it matter? And so. That's… that's just something that implementers would want to be aware of
… The big one here that gets discussed a lot is when users use a single did for lots and lots of things. It ends up creating a super cookie kind of situation where the actions that they're taking under the guise of those particular dids
… Um, it provides a very, uh, well-defined correlator identifier. Um
… And maybe sometimes that's good. Um, when a corporation, uh
… pushes out public releases. They want those things correlated. They want to be correlated with all of those activities, whereas an individual user communicating with different people might not want to be correlated. And so that doesn't mean
… that a single did is is wrong or bad. It just means that this is intended to prompt the implementer and users about how they're using particular systems
… and whether they meet their needs or or not. And so we've we've gone through and we've added a bunch of these and we plan on adding more. There's a couple of changes we might make to those diagrams up above
… And then as we make, uh, modifications in the resolution and DID specs, um, those changes over there would likely cascade, uh, down into this document as changes need to be made
… So, that's kind of an update of where we are right now. Um

Otto Mora: Mm-hmm...

Steve McCown: I guess, uh, that's all the overview I had, unless, um, are there any questions? Mm-hmm...

Otto Mora: Yeah, there's so Will's in the queue. But before that, and Philip had commented on the chat regarding the proxy referral threat. That is the use case for redirecting resolution to universal resolver. For example, he's asking...

Steve McCown: Yeah, um, so this proxy… I think, let me find the one you're referring to...
… I don't know, it's one of these, sorry
… They… yeah, uh, Universal Resolver is awesome, but it also carries, um, some
… potential threat risks associated with it. Who's operating it? How things get logged? Can some of your requests be then correlated? And we see the same exact problem with with the operators of a Dns. So this isn't
… pointing at the did resolver, the universal resolver
… For any reason or another, just that it, um
… It has a lot of similarities to did resolute, or excuse me, URL Dns resolution, and we're already working through those processes in society to accept and mitigate risks
… The intent of this was to say, um, there's a lot of similarities with DID resolution. Let's bring what we learned from over there over into our sandbox as well
… So, yeah, it does refer to it, but like I say, threats aren't necessarily
… a bad thing. They're they're more of a realization, a recognition that in certain instances different things can happen, and it's meant to prompt the user or the implementer. Do these matter to you? Does this affect what you're trying to do? And that's why I give the example of
… Like the correlatable did, when it's a company issuing a PR, that's a desirable thing. But when it's a user making private communications, it might be an undesirable thing. And so it's not inherently good or bad, it just has consequences depending on how you use it

Otto Mora: Okay, then final thing, it says, uh, Phil said it's Threat 13 Surveillance by Proxy… I don't understand, was it… is it that the title's wrong, Phil, or...

Phillip Long (GU, ASU): Sorry, I was looking at the document from the link, and in my link document...

Otto Mora: Mm-hmm...

Phillip Long (GU, ASU): That was external threat surveillance. Oh, it is 12. Sorry...

Otto Mora: It is spelled, yeah...
… No worries

Phillip Long (GU, ASU): Yeah, it is 12. Yeah, I thought I glanced at it and saw it as 13, my mistake...
… Thanks. And that was a good presentation, Steve. I thought that was clear
… and outlined the options that are rational and context specific. So it was well done

Otto Mora: Perfect...

Steve McCown: Yeah, thank you. Part of our motivation in doing this was to bring up these issues, because as we make enhancements to the core and resolution specs...
… if we put them through this kind of a lens of saying, hey, if I add this feature, which is really good, it has all these benefits, but then look at it from kind of the counter perspective of what would it mean in these other usage implementation scenarios
… then hopefully, we can catch some of these things in the design phase that might be a problem, or even if they're not a problem, then it helps implementers know, okay, because of my particular use case, I want to do it this way, or I want to do it that way

Otto Mora: Uh, Will, on the queue, go ahead...

Will Abramson: Uh, yeah, thanks, Steve. Yeah, this was interesting. I guess… um...
… My question is sort of, like, the master comment, right? We've kind of had a few of these sessions now where we've kind of overviewed the
… threat modeling progress, which is great to see. I mean, I have two questions. One is, like, when does this stuff get into GitHub so, like, potentially other people can contribute?
… also, like, how do we, like, move past, like, just overviewing the threats to a process where we're helping to produce or curate this? Like, I don't know, maybe that's just something that people need to take
… as a task for themselves, like, go in and review this document and suggest threats. Like, I just don't know where's the loop where other people are participating in helping produce this document. Or maybe that doesn't make sense at all, and you and Joe are gonna… get a bunch of threads together, and submit them to GitHub, and that's when

you'll be asking for people to review it. Maybe

Steve McCown: Excellent question, thank you. Yes, the intent is… so, Joe's out on vacation, uh, right now. He'll be back in a week or so. Um, and, um...

<pdl-asu> s/it's threat 13/it's threat 12/

Steve McCown: So, our intent is to get this into GitHub very soon, and while we've outlined a number of these threats, and we've got a couple of more that we want to add
… here we're… we've just put them together in a Word doc, but the, um, intent and the reason Joe wrote some of that code that I mentioned before for GitHub was so that when you go to
… the idea… here's the idea, is that you go to GitHub, and you've come up with this, uh, potential threat area, and you want to, uh, submit it using this model
… You should be able to go to GitHub, um, initiate an issue, and then have
… a button, I think is how it works, that populates this template. And, um
… And then, with that template, then the submitter can go and just add all the key areas, and try to make that as automatic for everyone. And then, just like any other issue, those can get resolved
… or formalized as the case may be
… And we want that to happen very quickly, and we want to make this simple for everyone. you know
… non-information security, uh, developers, so that, uh, whenever a
… uh, some, uh, potential threat or concern comes up, that they can be submitted. We want this to be very soon. We want lots of people, ideally everyone
… to be able to submit easily threats that they foresee. And then, as a group, we can discuss them, and hopefully, at some point, then formalize them into
… maybe a threat, recommendation, mitigation, document, or addendum to another document, or so forth. So this is in a word document format just for our ease of use right now. But we'd like to go live with that being. Something that, um
… Just like we raise other issues that it would be that simple that you see the template and then fill in the requisite information
… So soon, yeah, I don't have a, like, a date, but
… I'd say next few weeks it should be up and ready, and then we welcome anything anyone wants to provide, whether either by submitting a threat report or
… commenting or helping resolve. And by resolve, I don't mean resolve in the sense that we resolve issues today, but in this model where
… uh, uh, threat responses is… is kind of what I'm… what I'm pointing to, um, because different people might have different, uh, use case scenarios and would have different, uh
… views on how that would be resolved, and all of that should be documented, because they're all valid in different cases
… So soon is the answer. Sorry, it wasn't more brief

Otto Mora: Okay...
… Okay, Stephen Curran?

Stephen Curran: Yeah. My my question was probably already covered, but I just wanted to say it in a slightly different way...
… it is… I am worried about what is the next step and what we can do, um, so it sounds like we're waiting on
… Steve, you and Joe to come up with a templating approach to submitting these and reviewing these, and that's going to be how the process is. Is there… when did this have to be done?
… Um, is there a concern… is there an end date that… that this needs to be completed, or at least a first draft? And… and quite frankly, since these threats are
… you know, as… as we're coming up with them, essentially endless. What is good enough? Do we… do we have a definition of that? So
… How long do we have to do this, and what's… Good enough

Steve McCown: Good enough. That's an interesting question. I've always been told that overkill is underrated, so...
… No, I… I see this as more of a living document. Um… But
… I don't… I don't know if there's a particular, like, due date, like
… Um, you know, when the spec gets released, um, I'm just unaware. There may be, and I'm just unaware of that, but I do say this is a living document. I mean, even in the middle of, uh
… You know, after a spec's been released
… If there's a new threat, uh, with potential mitigation steps that comes up
… excuse me, that should be… that should be documented at that time when it… when it comes out. So, that's how I see it, and um… but I'm not always, you know, up on all the
… nuances of the W3C processes for publishing, but I think that would be helpful
… So, I'll have to get back to you on time frames

Otto Mora: Yeah, I also put myself on the queue just to add on our conversation with Joe last Friday. I mean, obviously, he would know better about timings and so on. But he said that his goal was to have 20 to 25 threats...
… on the public version of this doc, so that's enough for individual folks to be able to generate their own thread models for their DID methods
… But they're like the list. I guess the list need not be exhaustive like we can't possibly cover all of the threads. There will always be others, but. I guess enough so that
… Specific thread models for specific methods can be created, as I understand it

Steve McCown: Yes, absolutely. Umm...
… Dead Key, for example, has very unique threats that would be very different from. You know, um
… uh, checked, or BTCR, or something like that, um
… WebVH, you know, they'll all have different threats and responses associated with them, so

Otto Mora: Yep...
… Yes, Will?

Will Abramson: Yeah, my last comment is — I think maybe you touched on this, but my understanding from Joe is that this document is actually now going to be the DID threat model. I think you guys have aligned on the fact that we don't need two threat models...
… Um, we're probably just gonna have one, so this needs to cover, like, threats that are just from, like, the use of DID independently of DID resolution, or something like that, right? Like, you're not anticipating that we're gonna have a whole nother threat model called the DID threat model

Steve McCown: Correct. Yeah, we started out with this being a DID resolution threat model, and then what happened is a number of the threats we identified...
… were more related to DIDs in general, like the soup or cookie correlation
… And so, yeah, we thought we don't need two. We just need one, because DID users are going to resolve DIDs, so we might as well put all that all together

Otto Mora: Excellent. Wow...

Steve McCown: Rick...

Otto Mora: Okay, yeah, no, thanks so much, Steven. Uh, Steve, I really appreciate it. Great work...

Steve McCown: Yep. Thank you...
… And I'm open for questions offline if anybody has any other questions

w3c/did-resolution#344

Otto Mora: Awesome, thank you...
… Alright, so yeah, quickly on this other one, I guess more of a reminder, but we have this other PR, which is the referencing one
… Um, and, uh, I just shared your link there. I'll share it here on Zoom as well. But that's, uh, that's an ongoing one, and I know that, uh
… Quite a few folks have submitted some observations to it
… Uh, then Joe did some updates before he left
… Uh, then I think… I see, yeah, I see some, uh, inputs from Ted, and… Also from Stephen. So

Will Abramson: uh...

Otto Mora: more recent one for Marcus, uh… I know Will also did a few of his own, but I don't know, do we wanna discuss that? I see Will on the queue. Okay, well...

Will Abramson: Yes, am I… can you hear me? Yeah...

Otto Mora: Yep...

Will Abramson: Yeah. Yeah, my main comment on this was around… well, really, today, I kind of started to review it, and really reviewed all the commentary, got back up to speed, and I was...
… surprised to see Marcus's, like, pushback around, you know, this, uh… still talks about the URLs being resolved, not dids
… And it just gave me pause as to whether this is really the latest version of this. PR, like
… Uh, because I think we're all aligned, right, that we don't want
… to… we're resolving DIDs, not DID URLs. I think the only thing that might be why that is, is because this PR is really about the
… um… step 3, right? So maybe that's the only bit of the algorithm that Joe was focused on?
… Um… I don't know if people… No, no more. Yeah
… Um, but yeah, it would just make me wonder, like, because Marcus is right, like, but maybe this PR is just about… Direct
… Yeah, I don't know, basically, but I think the VR, as it stands, is definitely wrong and needs some changes, uh, if we want this PR to kind of finalize all of the five steps, right?
… Prepare, process… prepare, resolve
… Um, and all those five steps that we've outlined, which I think we do, so
… you know, maybe Joe dismissed it, or
… Or maybe he's not pushed all these changes. It's my worry now

Otto Mora: Yeah...
… Yeah, good point. Uh, David?

Stephen Curran: I'm wondering if it's just… I did find that note in there that said we're still debating it, and I'm pretty sure we've...
… finished that debate, agreed, and I'm suggesting that have to be… that note have to be removed
… But yeah, I was. I haven't fully read Marcus's comment, but I did some skim through it and saw that and thought, well, that's weird. I thought we had. Paul agreed we were going back to
… bids to be resolved. So yeah, agree

Otto Mora: Yeah. And...
… Joe's not back next week, right? He's not

Will Abramson: No, the week after we will...

Otto Mora: Okay...
… Okay, um… Yeah, I
… Well, well, let's let's let's you and I talk, Willie. I guess maybe if, if if this is this is a PR within
… the legendary requirements of GitHub, maybe you have the ability to correct it or not

Will Abramson: Uh...
… Yeah, maybe, I mean, I probably don't have time to do that. But I think, you know, independently of that, I think, you know, Joe is also on, like, we don't need to re-debate this thing, it's just a change that can happen later, but we can still have the other discussions, right, or you guys can have the other discussions around
… I think there are a few things in here. I mean, one of my concerns is that, you know, Marcus's issue contained a bunch of things, and not, you know, like, the DID URL thing is a fine and easy fix, but there are other things that Marcus's. Is, uh, pushing back on, and one of those is
… around the boundary of where does this video URL dereferencing algorithm end, uh
… you know, and he's still kind of proposing that it should be a URL, right? Like, we return the URL, and then let the client or the caller figure out what to do with it, and
… Yeah, so, I mean, you know, Marcus also isn't here today, and… but I know he's still
… I feel strongly about these things, so, you know, we've got to get through these discussions, and maybe we just have to override Marcus, but I just wanted to flag that, like, it would be worth people. Reading marks this
… comment in some sort of depth and replying to him with your thoughts. Great

Otto Mora: Okay, that's fair enough...
… Alright, so I guess that's, uh, that's the hallmark for us. I don't see anybody in the queue
… Uh, so I guess we'll end it here
… Perfect. Thank you so much

Minutes manually created (not a transcript), formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).

Diagnostics

Succeeded: s/have a debt resolution threat model discussion/have a DID resolution threat model discussion/

Failed: s/it's threat 13/it's threat 12/

Maybe present: Manu Sporny, Otto Mora, Phillip Long (GU, ASU), Stephen Curran, Steve McCown, TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com), Will Abramson

All speakers: Manu Sporny, Otto Mora, Phillip Long (GU, ASU), Stephen Curran, Steve McCown, TallTed // Ted (he/him) Thibodeau Jr (OpenLinkSw.com), Will Abramson

Active on IRC: JennieM, manu, ottomorac, pdl-asu, swcurran, TallTed, transcriber-bot, Wip