Meeting minutes
Introduction and Initial Discussion
Denken_Chen: I think Joe will be chairing for this call. Let me pin him. let's wait for a few minutes.
Denken_Chen: Hey So think let's get started. probably we start with SC PVR.
Joe Andrieu: Sounds good.
Scott Jones: Hi. Hear me?
Joe Andrieu: Yes. It's the bestselling shirt.
Scott Jones: Man, I used to have that shirt. That's Communist Party. Yeah. Wow. Joe Andrieu:
Joe Andrieu: That's right.
Scott Jones: That's from 20 years ago.
Joe Andrieu: Those guys had a great little business model.
Scott Jones: What was it called again? Yes.
Joe Andrieu: Threadless. Yeah,…
<Denken_Chen> Joe is coming in a few minutes
Scott Jones: That's awesome.
Joe Andrieu: I have quite a few threadless shirts. They're all a little worn and torn by now.
Scott Jones: Yeah, I remember I wore that to work and I really offended my boss. how many people have died under that flag, my god.
Joe Andrieu: I wore it to vote once and the person who checked me in was like, "Are you a member of the Communist Party?" And I'm like I paused because I'm like are you allowed to ask me that depends on the party.
Scott Jones: Yeah. if it's a party like this. Yes, I am.
Joe Andrieu: That's right.
Recap of Previous Actions and Updates
Scott Jones: Cool. Do you want me to recap I've kind of always started this by recapping what we're intending to do. I figure could You want me to recap that and then the actions taken?
Joe Andrieu: Yeah, I think that'd be great.
Scott Jones: Cool. So, section 5.3 is attempting to add a biometric vector confidence method to an issuer compact biometric vectors into a credential, not raw data.
Scott Jones: And when a verifier needs higher confidence that the presenter is a legitimate holder, a fresh biometric sample is compared against those enrolled vectors. The result is a signed verification credential with a non-binary confidence score. and then two scenarios, a client side local verification where nothing leaves the device and then a user selected provider where the holder picks a trusted biometric service. our last call two weeks ago I took actions on what we discussed last week I believe by the end of the week. so that was submitted as number 42.
Scott Jones: And the changes include renamed field names in JSON examples to match updated definitions that was biometric modality and specific names with generic examples as Manu provided guidance that there should be no vendor names in global standards. use case subsection with four paragraphs. So, age verification at a point of sale, account recovery, mobile credential presenter restrictions, and remote onboard added a sentence clarifying that issuers may include multiple vectors from different providers. challenge nons confirmed in verification output examples.
Joe Andrieu: Excellent.
Scott Jones: And then, tall had a bunch of editorial suggestions a couple days ago, so I batched and committed those.
CLR Labs Collaboration and ZKP Task Force
Scott Jones: And then in the Manu's threat model brainstorming doc, I added three threats to that. device compromise for client side verification, vector inversion risk, and biometric provider data misuse. and then one thing I just wanted to note, Manu mentioned Clar Labs, I believe is how it's pronounced in France, who have ZKP knowledge. I just kicked off the ZKP pseudonyms task force on Friday under the LFDT trust over sort of banner. lots of async conversation so far. this is my first time sharing such a thing but people watching it are excited. So it seems to be going in an exciting direction but all to say if they want to get involved now's the time and we're looking to have our first live call next Thursday or Friday.
Scott Jones: I can provide a link to a Discord channel if you want to hook them up or how else you might think they could get folded in if they're interested.
Joe Andrieu: That is a great question.
Joe Andrieu: Elaine, do you have any suggestions on the best next step? Go ahead, Ma.
Elaine_Wooton: I'm here. Go ahead, a. my thoughts are not gathered though,…
Manu_Sporny: So we were, go ahead, Elaine, because we both talked with them.
Scott Jones: That's what happens.
Elaine_Wooton: why don't you talk and…
Manu_Sporny: Okay. Sure.
Elaine_Wooton: then I'll talk.
Manu_Sporny: Thank you. so we had a great, conversation with the, CLR labs folks. …
Manu_Sporny: and I think total buyin to collaborate and work together to figure out how some of this stuff could work. Their focus is on kind of I mean they're coming at it more from the research perspective like education or not like university research perspective, right? So, a lot of their kind of time horizons are like, "Yeah, we would love to do some R&D on this, and we think we'll get the first version of that R&D out by, Q4 of this year, but it's going to take years for us to settle on something,…
Scott Jones: That's awesome.
Scott Jones: That's
Manu_Sporny: right? which is fine, right?
Manu_Sporny: because we do need to be able to get through this standardization process, we need to be able to at least demonstrate how this can work in a fully open, model so I they're very excited to work on this us. so I think what we might do is kind of send them your way, with some light kind of cross collaboration on RSpec. the only thing I think we need to look out for is I don't know what IP regime or policy LFDT and Toy operate under.
Manu_Sporny: Unfortunately, unless they've already got it figured out, we're going to have to get lawyers together to figure out how do we make sure that this thing doesn't become patent or IP encumbered with, Linux Foundation claiming copyright over it and not allowing W3C to work on it. that could create some challenges. So, just a heads up to you, Scott, to keep an eye out on specifically how we navigate that. we can, happy to put you in touch with the lawyers, but the second the lawyers get involved, it turns into a multi-monthlong exercise. so you might try to see if you can shortcut that by seeing if they already have some kind of collaborative agreement with W3C.
Scott Jones: Let's see.
Manu_Sporny: because we will ultimately need to pull whatever the CLR people are working on in I mentioned that early on…
Manu_Sporny: though we can include them as a invited expert in this group and as long as they release their stuff as open source that we should be fine meaning that's just because they're university and research that should be fine. so I think that is potentially that box ticked meaning that we can defend the specification like hey this is not some proprietary vendor grab there's an open version of it.
Manu_Sporny: If anybody wants to do better go right ahead. We work with both open models and…
Scott Jones: Okay.
Manu_Sporny: proprietary.
Manu_Sporny: models, the technology is agnostic to that. So, I think that's really good news all around. and as a next step, Elaine, I think we need to and maybe Joe and Denin, we need to get them into the invited expert process. one challenge the mention that they would have is that their French organization they will not engage with a US-based organization. Scott Jones:
Scott Jones: I love it. Okay.
Manu_Sporny: But luckily W3C in France Enria exists and they would probably deal directly with the European version of W3C so they don't have to be associated with there's a challenge there but I think it's easily surmountable.
Manu_Sporny: I think that's largely We just need to get them invited expert status and get them integrated in the group. And then Scott, we should do some introductions with you and then we would probably need to very clearly articulate to them like we need X, Y, and Z in this order. And if you could deliver it in that order, that would be great. for example, we need a matching model that does the facial vector as one of them. That's one component. The other component is we need a ZKP approach that operates on that facial vector matching model that you have. That's the second thing that we need from you. and each time you do that we need some kind of bundled open source thing that we can actually run and show people works.
Manu_Sporny: Sorry that was a lot but I think that's largely it from the outcome of that discussion.
Elaine_Wooton: Yeah. Yeah.
Elaine_Wooton: And I'll just add real quick. So the notion in the conversation was that as they work on their project, it's going to be open on GitHub and that. So, I think that makes it pretty simple that Mono said, the complication is whether they can participate on these calls with W3C. and I just got completely stuck. But I didn't realize there was this French version. So hopefully that'll work out and we can leverage this work that they're doing …
Elaine_Wooton: because I think it sounds great.
Joe Andrieu: Interesting. …
Joe Andrieu: have Mano, I have a question for you about if the source code is in a repo, that doesn't necessarily mean that we can use it in a standard. I don't know if you've tried to answer that question before with lawyers, I'm not a lawyer, but that's a question that seems to be relevant to us. Go ahead.
Manu_Sporny: Yeah. Yes, you're right. it needs to be under specific licenses. for example, there are licenses that are viewed as compatible with the W3C documentation and…
Scott Jones: Excuse me.
Manu_Sporny: and code license. So if you use BSD3 clause, you're fine because it doesn't create any restrictions on W3C using it. But if you were to use something like a Pharaoh GPL, I think that would violate it potentially. so we need to take a look at, what license they're going to use and just ask them to please use a license that's compatible with W3C and Linux Foundation, whatever. yes, also what Benjamin said, MIT, Apache 2,…
Manu_Sporny: those work just as well.
Joe Andrieu: Do you Yeah,…
<Benjamin_Young> Also MIT, Apache-2.0. Essentially "liberally licensed" OSS
Joe Andrieu: I have my doubts, but I think that's at least the right start. so there's still some hope of getting them to join in some way. It's just because of the American roots of the W3C, that's a little bit of a ruffle. but I understand they're going to go and commit to GitHub presumably with some sort of open source license and hopefully we can influence them to pick a license that's compatible with the wrinkle I'm worried about, Manu, it's not clear on those licenses if it means in with the use of this software. I can you extract the license to essential claims and not using the software.
Joe Andrieu: And that's where I'm like, I guess now lawyers need to chime in. Go ahead, Benjamin.
Benjamin_Young: Yeah, I'd probably need to see the repo,…
Scott Jones: Ready?
Benjamin_Young: but if you put up a collective work under a license like the BSD3 or Apache or even the GPL or any of those, the aggregate is licensed. But if there are no direct claims on any of the files that differ, then the contents of those files tend to be deemed licensed in kind with the aggregate. those who do thorough homework put the same license claim on every single file so it's clear.
Benjamin_Young: But in litigated open source cases, if somebody's put up a bunch of content into a collection,…
Scott Jones: It's This time
Benjamin_Young: if it's a zip file or a repo and there's a license file that says, this is all BSD3 clause, then somebody else could pick one file or even one chunk of a file and…
Joe Andrieu: interesting light.
Benjamin_Young: extract that and claim that they got it from this source that said it was part of an aggregated openly licensed thing.
Benjamin_Young: As long as somebody can prove the provenence later, Then you're fine.
Elaine_Wooton: Yeah, just to be clear the intention in this they offered to do this.
Elaine_Wooton: They want to have the small face vector that'll fit in a barcode open source. They want that to happen. So whatever hoops need to get jumped through or licenses or no licenses or whatever I think we can figure it out but their intention is for it to be open source and to be used by W3C.
Elaine_Wooton: So, we just had to figure out how to get that to work.
Joe Andrieu: Okay, that sounds good. I think my biggest concern that still is on the niggling edge, but I'll follow your confidence, Elaine, that their intention is honest and we can get there. It's around the patents. because licensing the use of a given file doesn't mean that the claims in the patent are licensed outside of that use.
Scott Jones: Yeah. Joe Andrieu:
<Benjamin_Young> It will need some sort of license for anyone to use it--because default is "unlicensed"
Joe Andrieu: And that's the concern. but we can figure it out.
Benjamin_Young: Yeah, if…
Benjamin_Young: if there are known patents around it, then encouraging them towards a pat an Apache 2 license choice might help there because that has essentially patent kill switches that say by open sourcing this we're not going to litigate this code even if we own the patent to it that we've let that happen. there's also kind of a standing belief with some lawyers that the BST3 clause implies that and apparently it's been litigated next to patents and has survived in that BSD3 clause code was released and…
Benjamin_Young: patent claims made against it and it was litigated in favor of the open-source BSD3 clause project.
Scott Jones: I'm sorry.
Benjamin_Young: That by doing both of those things, the company that open sourced their own patented code had basically done what the Apache more concretely says. but the Apache 2 license is the most on the nose about patents.
Benjamin_Young: And I'm happy to discuss this anytime.
Scott Jones: Yeah. Continue.
Joe Andrieu: Yeah, I kind of want to keep talking about it,…
Joe Andrieu: but we need a sandbox system to move on. I got to go look at that Apache Benjamin. my concern remains, but it may just be because to my mind that the copyright related licensing is around the use of that copyright. and so standards like ours, if we enshrine an algorithm that's patented and someone goes and implements it completely independent of this codebase, copyright wouldn't be in play, but the patent still so the case you cited may be absolutely right on and that maybe that's if they do XYZ
Joe Andrieu: and some courts at least have interpreted that as wider licensing. but that's where my fear factor is. Cool. Go ahead, Ben. Benjamin
Benjamin_Young: Yeah, that's where the express tent grant of patent license in the Apache license is helpful… Scott Jones:
Benjamin_Young: because the Apache 2.0 license covers more than just copyright. it also has this section about patent license. which is worth a read. It's like one paragraph. it's not going to kill anybody. you've said yes to more terms of services today than is in this one paragraph. So, it's pretty armchair lawyering that anybody can do.
Joe Andrieu: Yeah, I have to say, Benjamin, reading it, I think my concern is still there because it's about the work or contribution incorporated within the work.
Benjamin_Young: Yeah, we should tease this out offline probably and…
Joe Andrieu: So, yeah,…
Benjamin_Young: and come back to the group…
Joe Andrieu: it's an interesting question.
<Benjamin_Young> https://
Benjamin_Young: because Yeah,…
Joe Andrieu: In fact, I don't know, Manu, who in the W3C might we have a friendly conversation about this with?
Joe Andrieu: My thoughts are maybe historically Wendy, but I don't know…
Manu_Sporny: Rio. No.
Manu_Sporny: Rio winning.
Joe Andrieu: if she knows Rio.
Manu_Sporny: But I don't think you're going to be happy with the out.
Benjamin_Young: you're not going to get a super fast concrete answer Rio and Christine, but I'll also add that Ian Jacobs and I are working on an open source software creation policy at the W3C so that the W3C can actually house code as well. I mean it has code but more formally say this is a member created with an aggregate copyright by the W3C incorporated entity.
Scott Jones: Thank you.
Benjamin_Young: So we're discussing all of this stuff right now and there's probably a way to weave this specific story into that conversation. because patents have come up as how do we deal with these because patents frankly are why we have the W3C.
Joe Andrieu: That's right.
Benjamin_Young: Otherwise we'd be ITF, but W3C forked up the IETF to defend against patents. so we're at now this code moment for the W3C and…
Scott Jones: Stand up.
Joe Andrieu: Cool. Yeah,…
Benjamin_Young: defending against lurking patent trolls is part of what I want to make sure is covered. So if it doesn't feel covered, I'd love to bring you into those conversations so that we can address it.
Joe Andrieu: that sounds like an interesting conversation. Call me a legal nerd, but yeah, let's talk some more,…
Benjamin_Young: I'm clearly right there with you.
Joe Andrieu: Benmin. Yeah,…
Benjamin_Young: You buy the Guinness and I'll talk to you all day.
Joe Andrieu: we will have that conversation. That's right.
Benjamin_Young: right out of the fountain and don't bother
Joe Andrieu: Okay. thank you for the walk down…
Elaine_Wooton: CLR CLR CR CLR
Joe Andrieu: how we might engage these folks at is it…
Scott Jones: Let's go.
Joe Andrieu: is it CL A R. How do we refer to their R. All right. thanks for that conversation. I thought that was very useful. who's going to talk to them next?
Manu_Sporny: It is.
Joe Andrieu: It's cool.
Manu_Sporny: How about this? I'll send an email out or Elaine if you don't actually Elaine or I will send an email out with Denin, Joe, and Scott CCD to the chairs of the verifiable credential working group kicking off the process to pull them in as an invited expert.
Scott Jones: Excellent.
Manu_Sporny: That's the very next task and then we'll see where the conversation goes after that and then Scott feel free to engage with them independently and…
Manu_Sporny: pull them into your work and we can just kind of do some of this in parallel.
Joe Andrieu: Okay, that's great.
Joe Andrieu: All right, let's return I think checking in with you, in. Back to the PR. So, where did my PR Go ahead. Dang it.
Use Case Discussion and Placement
Denken_Chen: It's so very interesting about the discuss one question about the use case.
Scott Jones: You kiss me.
Denken_Chen: So use case is important for us to kick off the deals for biometric vectors in real world. And before talking about the details, I want to mention that we have another draft called the verifiable credentials use cases and in VCTM spec we refer to that draft for use cases.
Scott Jones: Thank you.
Denken_Chen: So I wonder whether that will be a better place to put together in all of the use cases and…
Denken_Chen: so we can point out to them. yeah I just paste the link about the C use cases. Yeah. Yeah. This job.
Joe Andrieu: Yeah, my take from the chat in Brussels on this was rather than trying to have all the task forces get full use cases integrated into the use case documents would be to have them add it to their own work and in the use cases document we refer to the different use cases because I think the barcode guys have use cases and the render method guys should have use cases I don't know if they do I haven't been following that…
<Denken_Chen> Verifiable Credentials Use Cases
Scott Jones: What is this? specific.
Joe Andrieu: but was that other people's takeaway from that go ahead Are you sure?
Manu_Sporny: Yeah, plus and in addition to that a birectional link where we point to the use cases document and we're like hey by the way there's a broader set of use cases around VCs that'll just get by the directional link going. and the other reason we're doing it is because of this weird mismatch between what the tag wants out of the main document. they want to use cases specific to the technology in the specification and it is much easier for us to just quickly get that together and refine it in the spec,…
Scott Jones: Still people.
Manu_Sporny: like confidence method spec and then once things settle then we can potentially move the more generalized versions to the main use cases document.
Manu_Sporny: So part of this is just a side effect of all the horizontal review people not necessarily asking for the in the same format. We're doing it specifically so that we don't have to generate a completely separate explainer document for the technology just for the tag itself. We're trying to put all the information they're asking in the spec itself.
Manu_Sporny: And use cases are one of the things they ask for. That's it.
Joe Andrieu: Very cool. Thank you, looking at the use cases that Scott's put together, I guess one question I have is would it make sense to have one section for the whole document or do we like that, for each confidence method, we would identify use cases specific for that confidence method. I'm not sure… Joe Andrieu:
Scott Jones: I'm not sure. Joe Andrieu:
Joe Andrieu: which way to go. Minute.
Manu_Sporny: probably just having one section because again this is a bit tail wagging the dog…
Manu_Sporny: but the tag asks for the section where you talk about your use cases and it was like they give you a link you can put in a fragment identifier to the document not multiple.
Scott Jones: That's what you're doing.
Manu_Sporny: They might have changed that but having them all in one place I think is useful. And then from the use case you can say by the way this use case is addressed in section blah blah blah blah.
Manu_Sporny: And the use cases typically go high up in the document in the introductory portions of the document. it's not ideal Joe.
Manu_Sporny: I mean I think the VC use cases document does a much better job of talking about the fcal use case extracting the requirements and…
Scott Jones: Is that There's something
Manu_Sporny: all that kind of stuff whereas these use cases are very like broadbrush high level just to give a paragraph of what you're trying to accomplish from the user's perspective I will note that we have four use cases for kind of biometric, video and image use cases. And I don't think we have one yet for the cryptographic traffic key one.
Manu_Sporny: So, we should probably add that to the use cases. Not in this PR, but I'm just noting that, having reviewed the PR. That's a
Joe Andrieu: Yeah,…
Joe Andrieu: I think I'd like that too. having a unified section would be good. I think some of these actually could account recovery by did off is possible. So I think that's what I think in general confidence method has a bunch of common use cases and…
Joe Andrieu: you could and sort of the whole point is you might get confidence via biometric you might get confidence via cryptography you might get confidence via something else let's do that Scott is move the use cases up to its own section that I think would be good and…
Scott Jones: All right.
Joe Andrieu: then I'm looking at the tail end of the use cases and Those all look like good property definitions. but usually that's in the data model. So I'm wondering if that was maybe we should move those term the property definitions in there.
Scott Jones: Got it.
Joe Andrieu: Go ahead.
Denken_Chen: It will just to add a little bit the VC use case is now the VC working groups group note. So I probably should add some PR to it and discuss in the main call. So that's the first thing and second thing is about the current use case. I'm very curious about when we are putting it back to the main use cases the loan documents it'll be more compelling to compare with existing use cases and…
Scott Jones: That's
Denken_Chen: why does it makes more sense to preserve the privacy by using this biometric vector verification stuff and it's also important
Denken_Chen: for us when adopting the digital identity. For example, any kind of biometric checking will help us to verify the presenter's identity. that happens a lot when doing online verification and…
Scott Jones: See that?
Denken_Chen: so for example in the age verification at the point of sale the first example usually it's on site so probably you can compare with exceeding solutions when you have a portrait just given with the verification so the point of sale can directly
Scott Jones: Excuse me.
Denken_Chen: compare the portrait with the person on site. But on the other side, when we are using this biometric verification, the people at the store will not even get your personal portrait image. So that's a plus for So this kind of comparison I think it would help us to differentiate the current use cases. Yeah.
Joe Andrieu: I followed most of that. What I wasn't clear of is if you recommending we do anything different than what Manu and I just put on the table in terms of the two groups referring to each other are the task force specs referring to the VC use cases and the VC use cases referring back. Were you proposing an additional or an alternative
Denken_Chen: Yeah, I'm proposing that we can do more in the VC group note really to introduce why the biometric vector is a better way in terms of biometric verification. So there I could also help on that part if we are going to write some paragraph in the VC group notes to compare with existing solutions.
Joe Andrieu: I so as a current editor of that spec, we would welcome if you're talking about adding a section that you want to highlight the distinctions between these different mechanisms, that would be welcome. We would appreciate that.
Denken_Chen: Yes, Okay.
Joe Andrieu: One question for you, Scott. …
Joe Andrieu: it sounded like as you went through the list, your intention was to address all the bullet points from our last review. and, do you think you did that or were there remaining ones that we should still talk about?
Scott Jones: I believe I did.
Scott Jones: And then the other things I had to track were things you said you would take.
Joe Andrieu: Okay.
Scott Jones: The verifiable presentation request examples and a provider model selection analysis. That's what the transcript says.
Joe Andrieu: Selection analysis. Did I say I was going to do that? Fair enough. I saw Tall Ted engaged quite widely on this. Did anyone else in the group have a chance to review this in depth? I mean, we all had a chance. Did you get in your schedule? Did you make the time to do it? Okay. I have not either. scanning through it.
Joe Andrieu: I guess I'm just confused. So maybe we could talk about where those properties go that you have at the bottom of the use case section.
Scott Jones: Please.
Restructuring the Document Sections
Joe Andrieu: So we're talking about 5.31. I could share my screen if that helps folks. So I'm in section 531 the use cases. I think we just agreed to move this up to a top level perhaps between three and four.
Joe Andrieu: And then we have these sections which are really property definitions and in fact a normative requirement about this data object. and so for one that's a little bit weird to have in a use case section. So probably goes somewhere else. We do have a data model. and I'm wondering how we would integrate it into here. I think the data model isn't really fleshed out fully enough to identify the properties. we need a data model for each of these confidence methods really and I think that's the gap in the document. Manu, I see your hand raised.
Manu_Sporny: Yeah, plus one to that. So, Scott, typically these documents are split into an introductory portion at the top. And so, that's really introduction,…
Scott Jones: for each one of these trick.
Manu_Sporny: conformance, and relation to the evidence property. The sections one, two, and three should be combined into one section. Conformance and relation, should be subsections. That's where you can also use cases. So, the use cases should probably go up there in the tro. and then you have a data model that just talks about this is what the data model looks like. And we should probably have a data model section for each one of these things. The biometric the image one and the did authentication one. this is one way to do it.
Manu_Sporny: And then you explain in the data model you'd move a lot of the section five kind of up in the data model just the introductory portion of this is what the data model's out.
Scott Jones: Okay. That's good.
Manu_Sporny: And then sometimes you have a totally different top level algorithm section that talks about the algorithms that you use on each data model. that is Another way to do it is to just say confidence method and for each confidence method have its potentially a separate use cases section. I don't know if I like that as much. there are positives and negatives to each approach, but typically what we do is the top level sections are introductory information and then the next top level section is data model and the next top level section is algorithms.
Manu_Sporny: And then the reason we do it that way is because in the conformance section we're like a conforming document is any document that adheres to the data model section a conforming processor is any processor that conforms to the algorithm section.
Scott Jones: Still pick up. Okay.
Manu_Sporny: That's typically why we do it that way. and you don't have to do this refactor, Scott. It's up to the editors to do it. I think just get the information in there and then the editors can, mess around with it till it flows. It I'm making it sound more complicated than it is.
Joe Andrieu: Yeah, I think that's so maybe we just give this a week and we could merge it in because I think most of what I've been talking about have been editorial,…
Scott Jones: Not that I'm aware of.
Joe Andrieu: put this section somewhere else. so Scott, the feedback that we've had so far, has any of it been non-editorial? Yeah, I don't think So maybe we just give folks I mean Manny, do you think we need to give folks a week? I mean, this is the second rev of updates based on…
Manu_Sporny: But I don't think it's a big deal it's a use cases thing like…
Joe Andrieu: what we talked about last week. right.
Manu_Sporny: what are people going to do object and then suggest some changes and…
Joe Andrieu: Also we're the task force,…
Manu_Sporny: and Yeah.
Joe Andrieu: So we're also separated from the group's official proposal.
Manu_Sporny: Yeah. Yeah.
Joe Andrieu: So this can't be taken as consensus of the group just because of how we're structured. Denin, what do you think? Do you have any objection to just go ahead and merge Scott's contributions in and…
Joe Andrieu: then we'll take the notes to restructure and I can take care of that?
Denken_Chen: Yeah, sure.
Denken_Chen: No problem. Can just merge with PR and move on to do the editorial things.
Joe Andrieu: Okay, Dave, go ahead.
Dave Longley: Yeah, I agree with that. I just want to note those properties are already in the spec today. So he's just making some adjustments to those in this PR. I also wanted to note and…
Dave Longley: I left a comment in the PR that the property list is sort of just floating not in its own section and it actually follows after in the HTML. If you look at the HTML it's floating after the use cases section just as a paragraph tag. So it's actually technically in the main subsection of biometric vector confidence method but in an awkward place. So, it'll be good when that gets moved around to address that as well.
Joe Andrieu: Okay, cool.
Joe Andrieu: Then Deni, you want to do the honors or shall I just need to get back to the PR. I had it up in preview mode. All right.
Scott Jones: It's just
Joe Andrieu: I do this all the time.
Joe Andrieu: Okay, I'm going to merge it Thank you, Scott, for the work. much appreciated. the editors will iterate on this. I do want to chat a little bit before we go about logistics. our next planned meeting, I will not be able to make it. as I will be on travel, that's the 30th. but, Dankin, if you can make it, I think the group can be productive without me. So, I don't want to suggest we cancel, but I want to check in with you, Denin, and make sure you can be there.
Denken_Chen: Yes, I can share that code and I expected to go through some of the early issues and I think most of them are canop market as proposed closing because we have addressed most of them and some are still ready for PR. We need to drip some PR for this and that's And one thing is like we need manual or Benjamin's help to assign me as the host of this Google meet.
Scott Jones: Thank
Denken_Chen: For me to host that later. Yeah. This money.
Manu_Sporny: Yeah, I can do that. I thought you were already a co-host, but if not, I'll definitely make you one. I think I need a Google account from you. That's the thing that enables you to kind of start these meetings.
Denken_Chen: Yeah, no problem.
Manu_Sporny: Okay, great. Thank you.
Joe Andrieu: Okay. …
Joe Andrieu: anything else we might want to talk about, Denin? This feels like a good chunk of work, man.
<Denken_Chen> denkenie@gmail.com
Horizontal Review Preparations
Manu_Sporny: I do have one question and apologies. We might have talked about this a month ago and I've forgotten, but what are we expecting for the did and biometric sections?
Scott Jones: That's what
Manu_Sporny: I'm wanting to get us into some kind of horizontal review, sooner than later.
Manu_Sporny: And so we need threat model. We need to did a biometric confidence sections. who has those tasks? Because I'll take one of those or two of those if we don't have someone for it.
Joe Andrieu: Yeah, that would be great. my understanding and my personal commitment given the travel I'm about to be going on was to be ready for horizontal review by TPC. and that does mean we need some drafts ASAP. I think Denin you were planning on doing the biometric image one. I don't know where that is in your priority queue. I had been expecting to did off one, and we have at least three different, types of did off that we need to document and figure out. so if you're comfortable tackling that, I mean, I could give you the Do when I say the three ones, is that obvious to you or is that … Joe Andrieu:
Manu_Sporny: No, but if you what they tell me what they are, I can take it from there.
Joe Andrieu: Yeah, that would be So the three did go use the authentication method in the it is a verification method that is pointed to by did URL right all the way to the key one or…
Manu_Sporny: Okay,…
Joe Andrieu: whatever the identifier is for that particular verification method. and then the third one is it's an embedded verification method. So all the material is there. ideally using the exact same data scheme that we use for verification method in DID documents or SID documents.
Manu_Sporny: I can. Yeah, those are Easy. I might ping you just to get those again.
Joe Andrieu: No, I'm happy to engage, but the other things I'm trying to get through editing.
Manu_Sporny: Yep. Yeah,…
Joe Andrieu: So I would appreciate that if you're in a position to help.
Manu_Sporny: sure thing. No problem. And then what about threat model?
Manu_Sporny: I can take a first rough cut with one threat per category if that would be helpful. or
Joe Andrieu: The trick for us,…
Joe Andrieu: I think, is that we do need a diagram. I think that's the hard part.
Manu_Sporny: Yeah. Mhm. Okay.
Joe Andrieu: And what I just paused on was do we need a diagram for each of these different kinds of methods? I think so certainly the biometric stuff has a device in there that the did off probably doesn't. so to me the hard part is coming up with the diagram that works effectively. so I would start there. but happy to have some help. I had this conversation actually with Eric about VCOM and whether or not he wanted me to who really have a role as an editor with that threat model. and I'm like I want to help other people be editors of that.
Manu_Sporny: Yeah.
Joe Andrieu: Let me coach and advise because I'm just kind of overwhelmed with my volunteer obligations right now. Denin
Denken_Chen: So first I will keep up with PR for biometric and I propose that for example I'm responsible for biometric and Scott is ironing the biometric vectors and then the proposed that each of us responsible for ourselves write us some paragraph of security considerations because that also will help the diagram you're mentioning to cover all of these confidence methods.
Joe Andrieu: Did you have more, that all sounds good. anything else worth covering today or we can wrap a few minutes early? Okay, I think that means we're good for this week.
Scott Jones: Thank you. Bye.
Joe Andrieu: I will not be here two weeks from now, but we will be meeting under Denin's leadership and hopefully that'll be good and productive. So, see you guys hopefully in four weeks. Cheers.
Denken_Chen: Thanks, Joe.
Manu_Sporny: Thanks Meeting ended after 00:50:25 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.