14:04:45 RRSAgent has joined #vcwg 14:04:49 logging to https://www.w3.org/2026/09/09-vcwg-irc 14:04:49 RRSAgent, make logs Public 14:04:50 please title this meeting ("meeting: ..."), ivan 14:04:56 Meeting: Verifiable Credentials Working Group Telco 14:04:56 Agenda: https://www.w3.org/mid/69dd7d722cea187c8fca8acbae37e5d4@w3.org 14:04:56 chair: brentz 14:04:56 ivan has changed the topic to: Meeting Agenda 2026-09-09: https://www.w3.org/mid/69dd7d722cea187c8fca8acbae37e5d4@w3.org 14:50:26 bigbluehat has joined #vcwg 14:59:11 pdl-ASU has joined #vcwg 14:59:16 present+ 15:00:59 exe has joined #vcwg 15:01:50 hsano has joined #vcwg 15:02:18 present+ 15:02:33 present+ 15:03:20 present+ 15:03:31 brent has joined #vcwg 15:03:39 present+ 15:03:43 KevinDean has joined #vcwg 15:03:46 present+ 15:04:03 JoeAndrieu has joined #vcwg 15:04:14 JimR has joined #vcwg 15:04:17 JennieM has joined #vcwg 15:04:25 present+ 15:04:39 saad has joined #vcwg 15:04:52 present+ am, tallded, jimr, exe, wes, elaine, ingo, dmitriz, msporny 15:04:57 michaelshea has joined #vcwg 15:05:03 present+ 15:05:41 wes-smith has joined #vcwg 15:05:43 scripe+ 15:05:46 scribe+ 15:05:47 present+ michaelshea, joe, bigbluehat, saad, kezike, jennie 15:05:58 present+ 15:05:58 s/scripe+// 15:06:19 present+ wip 15:06:35 brent: Welcome to today's meeting. Is there anyone who would like to introduce themselves? 15:06:39 kezike has joined #vcwg 15:06:47 present+ 15:07:17 present+ eva 15:08:10 ... Our agenda today - we will get updates from the task forces, discuss a proposal about publishing a suite of threat models, and do some reporting on the Global Digital Collaboration Process (?) 15:08:26 q+ 15:08:45 Topic: Task Force Updates 15:08:58 ... If you lead a task force please let us know how it is going. If there are issues or PRs that this group should pay attention to, please let us know. 15:09:03 ack manu 15:09:32 VCWG Task Force deliverables tracker: https://docs.google.com/spreadsheets/d/1OM-UsLnOZKywcy1eSGZsi_laCHBIy5wmQFOer0a7kYI/edit?pli=1&gid=67467047#gid=67467047 15:10:12 manu: At a high level, we're doing well from a horizontal review request perspective. We have multiple requests out, for Render Method, VCALM, barcodes, and recognized entities. 15:10:26 ... I have a question to the group around when we want to send out the requests for minor version specs. 15:10:44 ... Also note feature freezes - not every spec that we requested horizontal review for is at feature freeze right now. 15:11:26 ... For recognized entities, we are down to the last set of issues to go into candidate rec. We can put that as a feature at risk - it is trying to address a need from GS1/the supply chain traceability work. 15:11:34 q+ michaelshea 15:11:58 ... Isaac has not been able to edit that spec as much as we would prefer. Stephen Curran is a potential editor, who I believe is in the group as an IE. 15:12:21 ... Recognized Entities is a couple weeks away from going into CR if we want to go that route. We have only heard back from i18n. 15:12:26 ack michaelshea 15:12:48 michaelshea: Is the expectation that controlled identifiers should be going to horizontal review, or is that not appropriate given where it is? 15:12:59 q+ 15:13:14 brent: the updated version of controlled identifiers should go through horizontal review, but only the diff need to be reviewed, generally. 15:13:20 ack ivan 15:13:36 q+ for VCALM update 15:13:42 ivan: In my recollection, there were no technical changes to that document so far. If there are only editorial changes we may have to notify the horizontal groups but will not have to do anything major. 15:13:52 michaelshea: What is the deadline for that? 15:14:12 ivan: Let's table that since it is one of many minor versions. 15:14:33 ... My personal take is to postpone that until after the others have gone to CR. 15:14:54 q+ for confidence-method update 15:15:00 ack kezike 15:15:00 kezike, you wanted to discuss VCALM update 15:15:17 https://github.com/w3c/vc-data-model/issues/1649 15:15:35 Wip has joined #vcwg 15:15:42 kezike: We are in a good place w.r.t horizontal review. Just yesterday, we added a new issue that might be good to discuss. It's relevant to the VCDM spec, where we want to add a new term in the 2.1 context to support BBS and other features. 15:15:49 present+ 15:16:00 q+ 15:16:13 ... Another more general thing is that there are still failures with the deployments - they are not updating when we push to prod. I want to make sure W3C folks are looking behind the scenes, as we are having to use outdated links. 15:16:22 ... TR space is still not getting updated when we push to main for our specs. 15:16:26 ack JoeAndrieu 15:16:26 JoeAndrieu, you wanted to discuss confidence-method update 15:16:53 https://github.com/w3c/vc-confidence-method/pull/43 15:17:36 JoeAndrieu: Two things related to this chart. The feature freeze and threat model should be half. There is some debate on a current PR that could use attention from the group. We have started a threat model - the key trick we are working through is, within confidence method we have different confidence methods and assurance levels. 15:18:24 ... Our diagram either needs to address all of it or we need to have multiple diagrams. We are teasing out the best structure here. Our intention is to have the spec text and our submissions for review request in place by TPAC. 15:18:42 ack manu 15:19:07 manu: To respond to kezike, I have been able to push things to TR space, so what is broken may be specific to VCALM (or a transient error). We can take it offline. 15:19:12 q+ 15:19:20 scribe+ 15:19:26 ack wes-smith 15:20:37 wes-smith: VC Barcodes/ DI update: we are in a fairly good place. Review is requested for barcodes. Still ongoing work for DI, given that there are other related specs in it. Planning to put out review for VC Forgery spec. Doing update for Biststring Status List. 15:21:13 Topic: Threat Model publishing 15:21:26 q+ to propose something 15:21:30 ack manu 15:21:30 manu, you wanted to propose something 15:21:36 brent: Next topic is threat model publishing. Is there more to it than publishing threat models as notes? 15:22:12 manu: There is just a bit more. We have to decide what the short names will be as well as publication dates. 15:22:16 pdl-ASU has joined #vcwg 15:22:22 present+ 15:22:24 q+ 15:22:38 ack wes-smith 15:22:44 q+ 15:22:55 ack manu 15:22:55 q+ 15:22:59 wes-smith: Is the threat model coupled to the version of the underlying document? 15:23:10 manu: They shouldn't be versioned since they are living documents. 15:23:16 q+ to discuss version and multiplicity 15:24:08 ivan: The note can be a living document that is still bound to a versioned document. 15:24:11 ack ivan 15:24:18 ack JoeAndrieu 15:24:18 JoeAndrieu, you wanted to discuss version and multiplicity 15:24:38 q+ 15:25:23 JoeAndrieu: +1 to the framing, but I think we should have versions on the model itself. It is not a registry which is a living document. As soon as the WG goes away we can't edit that document any more. The other thing I wanted to point out as a point of socialization is that, one thing we want to be careful of is imagining there is only one threat model for every spec. There could be multiple documents with different focuses. 15:25:53 ... Those tend to want to have different documents and diagrams. We are streamlining a way to publish so that each spec has an easy way to get through the publication process. This is making it easy to get a first version out. 15:26:00 ack manu 15:26:23 q+ 15:26:28 ack ivan 15:26:39 ivan: is the version in the proposal the version of the document or version of the threat model? 15:27:33 q+ 15:27:45 ack JoeAndrieu 15:28:11 q+ 15:28:19 JoeAndrieu: There are two relevant versions - the underlying spec and the threat model 15:28:36 +1 Joe, there are two relevant versions, don't know the best way to express that in a short name. 15:28:51 ack manu 15:29:28 q+ to say that general threats are fine. but the model is spec-specific 15:29:37 manu: I think threat models should not be versioned, but these things are meant to live more broadly. 15:30:30 ... There could be tooling issues with putting versions in the middle of a shortname. 15:30:55 q+ 15:31:17 Even if we claim that every version of a spec should have a threat model, I don’t imagine that one spec version would have multiple threat model versions. For this reason, if we MUST add a version to the shortname of the threat model note, I think we can just borrow the same version of the spec. 15:31:18 ack JoeAndrieu 15:31:18 JoeAndrieu, you wanted to say that general threats are fine. but the model is spec-specific 15:31:51 JoeAndrieu: You've convinced me that having it in the middle is too awkward, but I push back against the idea that threats are for a generic version of the spec. That would make them ungrounded. The value of threat modeling is that it is embodied. 15:32:16 Ingo has joined #vcwg 15:32:30 ack ivan 15:33:10 I would suggest that the test suite URL made the wrong decision :) 15:35:38 q+ 15:36:15 q+ 15:36:19 brent: If we update the threat model for the VC data model 2.1, do we just update the threat model? 15:36:21 q+ 15:36:26 ack JoeAndrieu 15:37:10 JoeAndrieu: I think we should version the threat models, I don't know that the versions need to propagate into the shortnames/URLs 15:37:11 Let's not do two versions in a URL. :) 15:37:16 Agree w/ Joe's proposal. 15:37:18 ack ivan 15:37:21 q- 15:37:35 ivan: +1 to Joe, we can change the title and version number without changing the URL 15:37:49 PROPOSAL: Publish all Threat Models created by the VCWG as NOTEs. The shortnames for the threat models should start with the unversioned shortname of the associated specification, and then "-threat-model", and then "-" (where VERSION is the version of the associated specification). The threat models should be published at the soonest reasonable publication date as determined by Editors, Chairs, W3C Staff, and Management. 15:37:53 +1 15:37:55 +1 15:37:56 +1 15:37:58 +1 15:38:00 +1 15:38:00 +1 15:38:01 +1 15:38:01 +1 15:38:04 +1 15:38:09 +1 15:38:15 q+ 15:38:26 +1 15:38:49 RESOLVED: Publish all Threat Models created by the VCWG as NOTEs. The shortnames for the threat models should start with the unversioned shortname of the associated specification, and then "-threat-model", and then "-" (where VERSION is the version of the associated specification). The threat models should be published at the soonest reasonable publication date as determined by Editors, Chairs, W3C Staff, and Management. 15:38:55 brent: hearing no objections and seeing nothing but +1s, we are resolved. 15:38:56 ack ivan 15:39:18 ivan: One request is to send me three URLs for three threat model documents so it's not too abstract. 15:39:28 Antony has joined #vcwg 15:39:34 Topic: GDC Report and Q&A 15:40:37 brent: Our last topic is GDC report and Q/A. Last week was Global Digital Collaboration in Geneva and attended by more than 2000 people - which is a 3x increase from last year. This is a conference that attempts to be a little bit of everything digital identity, primarily on the use case side. 15:41:35 s/GDC Report/Global Digital Collaboration Conference (GDC26) Report/ 15:42:34 ... Largely the conference was focused on mDL rollout - there were sessions that talked about ZKPs, age assurance, and identity for AI. 15:42:51 ... There was also substantial discussion about trade modernization. 15:43:14 how was the discussion on SD-JWT vs. JSON-LD based credential formats going - if at all? 15:43:20 q+ to ask if there are any actions for us from the conference? 15:43:49 Elaine has joined #vcwg 15:44:20 brent: There was very little conversation about data formats - most presentations just said "Digital Verifiable Credential". Most specifics were around mdoc. 15:45:08 ack manu 15:45:08 manu, you wanted to ask if there are any actions for us from the conference? 15:45:54 manu: What we (Digital Bazaar) are experiencing is that people are moving beyond talking about data formats/protocols - there is an expectation that everyone will support everything. That is at least our experience in North America. 15:46:35 ... I'm curious what W3C said as an organizer? I know PA was there, I think I saw a picture of Dom on stage - I'm curious to hear what W3C was saying. Question 2 is whether there are any actions from the conference. 15:46:58 ... Is there anything actionable happening, or is it just yet another identity conference where people talk about latest learnings but without movement on the technical side? 15:47:17 GDC 2026 Book of Proceedings: https://docs.google.com/document/d/1fPR-C59zIIARzcfLnyFrSq1SASGkocJCbbh0uKPY3bc/edit?tab=t.0 15:47:40 i was there - i saw simone talk about age assurance - nothing profound 15:48:00 brent: I didn't attend most of the W3C centric sessions, so I wasn't in the room for a lot of that - but much of it was DC API conversations. The W3C took part in some threat modeling exercises for age assurance. 15:49:07 Did any attendee notice, was there any distinction drawn between W3C (D)VCs and EU D(V)Cs? 15:49:25 ... As far as what this group should do, one difference that I noticed between (and this is systemic more than anything) W3C vc OIDF - the OIDF was very deliberate in the things that they supported and the sessions they proposed, whereas W3C had things that team members wanted to touch on, but for the most part sessions were left to W3C members to propose. 15:49:42 ... There was less top-down-organized "here is how the W3C is going to engage with this conference". 15:50:00 ... Next year it may be beneficial for at least our group to say "here is what we want to happen at this conference". 15:50:02 q+ 15:50:08 ack michaelshea 15:50:17 q+ 15:50:40 michaelshea: I wasn't able to attend the GDC this year, but your description sounds spot on. I was there last year. Historically it's very focused on personal identity, but what you are describing sounds very much what I would expect. 15:50:56 ack Elaine 15:51:10 q+ to ask whether there was any distinction drawn between W3C (D)VCs and EU D(V)Cs 15:51:26 q+ 15:51:36 ack TallTed 15:51:36 TallTed, you wanted to ask whether there was any distinction drawn between W3C (D)VCs and EU D(V)Cs 15:51:56 TallTed: Wondering if there was a distinction drawn between W3C VCs and the EU's Digital Credentials, which have been blurred a lot over time. 15:52:13 brent: For the most part they were not talking about what we are talking about. 15:52:13 Elaine has joined #vcwg 15:52:17 unless in the trade area. 15:52:26 TallTed: That is problematic, especially given that W3C was one of the organizers. 15:52:28 my internet went out - of course 15:52:29 I think that's by design Ted :) 15:52:31 q+ 15:52:38 manu +1 15:52:46 ack pdl-ASU 15:53:25 pdl-ASU: the Swiss Digital ID had some pragmatic discussion previously at the conference. 15:53:25 ack manu 15:53:58 manu: To reflect on what TallTed said - the coopting of the term "Verifiable Credentials" was an intentional choice. The umbrella term appears to be "Digital Verifiable Credentials", which include all the formats. 15:54:21 ... There is a group that is trying to dilute what the term Verifiable Credential means. 15:54:55 I went to the interop Sunday and Monday before GDC at IATA - it's all mDOC - if W3C wants to be seen, there needs to be a way to participate - I don't know what that is - someone from MOSIP came to the one in Bangkok and of course, there was no "interop" for them 15:55:22 ... That said, note that California talks about its digital credential program as "the mDL program" - but most of the credentials they issue are W3C VCs. 15:55:25 If Credence can read the CA DL then we should show up with that physical document and have it succeed 15:56:04 +1 an "mDL" can be (and often is) a W3C Verifiable Credential -- the terminology is quite fluid in the space. 15:56:23 q+ to voice things 15:57:10 ... Item two is that I am, as a W3C member, displeased with the lack of W3C leadership around the W3C Verifiable Credential work. Leadership is not engaging with opportunities, the messaging is sloppy, and the OIDF is doing an excellent job. I am disappointed with the way W3C has engaged with GDC, and there are many lost opportunities there. 15:57:16 ack brent 15:57:16 brent, you wanted to voice things 15:58:35 problem is that the two (or more) are not interoperable 16:00:04 particularly since they were a sponsor... 16:00:14 q+ 16:00:40 ack manu 16:00:43 q- 16:02:04 rrsagent, draft minutes