Meeting minutes
Brent Zundel: Welcome everyone, we'll get started in a bit
Brent Zundel: This is the primary telecon for the week, we are meeting under the W3C following the IPR , code of conduct, and process of W3C.
Brent Zundel: Our agenda for today -- we will start with a brief look at the digestSRI issue, we will go into task force updates, we'll talk briefly about relationship between DPP and RecognizedEntities, a bit about TPAC and GDC, and then the primary focus is a conversation about threat models.
Brent Zundel: please feel free to provide changes/additions to agenda
Manu Sporny: There is an internationalization issue we should cover.
Ivan Herman: Perhaps we should have Jim introduce himself?
James Richards: I am Jim Richards, CISO for ONEPROOF, doing digital IDs and ISO and OpenID harmonization. Prior to thsi work 20+ years work in government, security architect of Wisconsin RealID, worked a lot in physical ID speace, some in digital ID space.
James Richards: I have experince for European Manu Spornyfacturing company, UK, and Germany, dealt with privacy laws there.
Carolynn Bernier: I have a question, can we ask about Recognized Entities work?
Brent Zundel: Yes, we have a RE and DPP item coming up, would it fit in there?
Brent Zundel: if it doesn't fit in that conversation, make sure to mention it.
Brent Zundel: Let's take the i18n issue first.
Internationalization issue
w3c/vc-data-model#1641
Manu Sporny: Re: 1641, the internationalization group gave feedback during the horizontal review, that we were being inconsistent in our use of string values , and we need to be specific about when strings are localizable.
Manu Sporny: the current proposal is to add a new term for a localizable value in the verifiable credential data model.
Manu Sporny: I can raise the pull request unless there is an objection, or if someone has a better way to address this issue.
Ivan Herman: I have no objection, there is separate vocab specification. The tool has been upgraded to address the features Manu Sporny expressed, but the work needs to be done
Joe Andrieu: +1 to management proposals, coming up with a term for what is localizable. How do we deal with images, because it is not covered and there may be no solution.
Manu Sporny: +1 to that Joe, I think this one is specific to string values, hyper focused, trying to solve the hyper focused thing, we're vague when we say string, need to fix that
Manu Sporny: other can of worms problem, absolutely struggling with that in Render Methods spec, tag render template with thing - images, audio, everything covered, person viewing has said they have arabic as localization, I'll go to arabic template . . .
<Dave Longley Longley> +1 that "within the template" using the HTML render method might solve a lot
Manu Sporny: other alternatives as well, active points of discussion in render method if you want to help there
Brent Zundel: sounds like we have a path forward, plus additional conversation . . .
DigestSRI/DigestMultibase
w3c/vc-data-model#1628
Brent Zundel: issue recommends deprecating DigestSRI as related resource . . .
… right now the VC Data Model supports two options, DigestSRI and DigestMultibase, issue recommends deprecating to rely on Data model, significant pushback from dev is Japan making use of DigestSRI . . .
… happy to take comments, Shigeya's schedule making it difficult to attend call, may be channeling his thoughts, and may need to put off to TPAC . . .
Phil Archer: what to help group move forward, came up in our F2F in June, noted at the time Shigeya's response, which was impassioned . . .
… if I wear GS1 hat, no skin in game, approaching purely as Brent Zundel's co-chair, what I see is one very influential company pushing for something, and I see another member of the group, eminent professor in Japan, arguing against . . .
… mentioned those features of Digital Bazaar and Shigeya, had one-to-one with Shigeya recently, thinks deprecating would be real problem, doesn't want it to happen. Others want it to happen, what would be middle ground, not forcing anyone to implement anything they don't want to, unless you get to a spec . . .
… would Shigeya be willing to add open source code, he said yes, and in the last 24 hours has argued his case with evidence, Dave Longley has responded, seems to me it is a feature in VCDMII, would cause harm if deprecated . . .
… personal view is that DigestSRI should stay . . .
Manu Sporny: thank you for the summary, only part I disagree with is the framing that this is coming from one org, discussed this in great depth during recognized entities call, +1s from lots of people on the call, deprication doesn't mean removal, just stop using it . . .
… technical issues if we keep using it, more than one company weighing in on this, don't know anyone else fighting hard for this feature except for one org in IETF . . .
… concern I have is that we are not making a technical decision if we keep it in the spec, making a political one, don't think it is a good thing to do. Will world explode if we keep it in the spec? no, and not a good thing to use too much of the group's time, but it will keep coming up if there is push to use DigestSRI, will just move into the task forces.
… I'm happy to leave it alone if we should be making a political decision over a technical, but we should move on
Brent Zundel: just in general, the way we have tended to do things in the working group is to support people in the things they need to do their work, as long as it doesn't keep others. historically having more than one option to do things has been the way we've done things
… I think it is technically better to choose one, but our path forward is to error correct, or to continue on. In other cases, for this spec we are using VC Data model, and must use DigestMultibase, is this an option, would this alleviate some of the difficulties
… spend 5 more minutes
Dave Longley: that might alleviate some of these things, some may need their own guidance in what they should pick. Don't think it would be good to leave it open and have this come up with every other spec, would prefer us to say in VCDM to recommend one over the other...
… that being said, DigestSRI may have a problem, linking to a spec in working draft status that is in perma-working draft status...
… just incidental fact that hash algorithms in spec have been historically stable, if one removed, we'd have a gap. More or less what I made in my comment, really only have the appearance of compatibility because we don't use processing rules, will have this gap, won't work right...
Brent Zundel: would help to adjust to say that DigestMultibase is recommended, significant issues relying on DigestSRI
Phil Archer: Shigeya has volunteered to write more
Manu Sporny: +1 Brent Zundel, do think profiling is the way we've done it, we should do it this time, what we tried to do in recognized entities spec; +1 to what Phil said, don't want to make decisions without people in the room...
<Phil Archer> phila: Also noted that the Rec Ent TF call is at 05:00 Tokyo time so an issue that is of particular interest to anyone in Japan can't be resolved at that time.
Manu Sporny: not consensus to add DigestSRI, profiling may work, don't want to spend much time in the group talking about it, but if we don't come to a decision, it will continue
Brent Zundel: timing-wise for spec, chair hat off, personally, I'm fine, and Phil is fine putting this off until TPAC when we can solve in a room together, but that feels like that may impact timelines, so final question is - is putting this off until TPAC an option?
Manu Sporny: we can put it off until TPAC, editors can say we haven't quite figured this out, but can go into candidate rec stating that...
<Ivan Herman> +1 to Manu Sporny
Manu Sporny: most fair thing to do is wait until we have everyone the room
Task Force Updates
Wesley Smith: brief update for barcodes and data integrity, call for horizontal review is now out, data integrity is progressing at good clip, ongoing work on selective disclosure. Work also going on with forgery defence hope to get the call out in the next few weeks
Kayode Ezike: main two things to note are that we've submitted requests for review for accessibility and internationalization, security and privacy in the next couple weeks, after resolution last week able to submit IANA registrations for “interaction” and “web+interaction” URI schemes, should resolve soon. After which, we should have URIs reserved for us
Brent Zundel: possible request for Ivan Herman to check on ianna
Kayode Ezike: asked for a personal contact to use, seems like Ivan Herman is best choice, only things outstanding for URIs to be reserved
<Dave Longley Longley> +1 to get the registration and then make contact adjustments as needed
Ivan Herman: fine to use my name, or mine with Manu Sporny's, but not a long-term solution. once registered, we should put contact name back to working group.
Brent Zundel: is there a W3C liaison address we can use?
Kayode Ezike: this is just for the request
Manu Sporny: a number of us working on threat models are trying to figure out the right way to publish those, just a heads up to the group, trying to figure out publication process. Trying to make it easy on everyone, stay tuned
Denken Chen: confidence methods, task force decided to keep original name, add assurance levels as well, and to keep short URL names. Almost finished with first draft, will hopefully start in to discuss threat modeling at the next meeting
DPP + Rec Entities discussion
Carolynn Bernier: so, Monday, in DPP task force, Ivan Herman told us about the work going on in Rec Entities, discussed it, Ivan curious what is the relationship between the two...
… turns out the two examples provided in Rec Entities are very close/relevant, Ivan Herman wanted to know if it would make sense to add a DPP specific example in spec...
… don't have an opinion, would it make sense to add a DPP specific example...
… have one on GS1 and one on trade documents
Manu Sporny: yes, we should do this. I think we should add a DPP use case to appendix, would love to get input on what it should be. Overlap, but it is not a replacement overlap. Related, but Rec Entities is focused on chain of entities to top root of trust. Would love to put examples in, just let us know how...
… some of us are happy to come to DPP group, just let us know when to do that
Carolynn Bernier: I was reading the spec from Rec Entities, chapter 4 is on discovery algorithms, which may be a better name for the title of the chapter ...
… examples in appendix B illustrate to discovery algorithms, but real question is - is there a plan/discussion on the pros and cons of the two discovery algorithms? way to have the conversation, or place in the document? spec recommending two...
… have working relationship with people working on SDJot, asked them how they do discovery in their context, started to get some reactions from them...
… could be interesting as we are considering pros and cons of different approaches
Phil Archer: Carolynn Bernier, let's chat offline, certifications certainly the big use case, I think an example in there...
Manu Sporny: two discovery algorithms, yes different appendices point to each one, trying to get implementers to tell us which they prefer and why, benefits and drawbacks in both. Afraid to say something to early as people are still figuring it out. Not an expert in SDJot, know in implementations we've had to do they tend to just depend on x509
certificates, do speak to a bit of that in spec...
… vc data model, group exists because x509 certs have limitations, seeing these as they are deployed in trust infrastructure in mdoc and mdl, not going super great, but tends to be what sdjot and mdl rely on. Danger of putting a this is what is good and this is what is bad on it is that we end up in endless discussion and that burns a lot of time
… things have shifted, don't think anyone enjoyed the process, drove a wedge between the groups and I'm reticent to do that. Here are the reasons to use each, and mark that implementors decide, rather than picking a fight
Brent Zundel: sounds like we have steps forward, last topic is TPAC
Joe Andrieu: my request is short, is there a way we could get the calendar to remove cancelled meetings? duplicate meetings, unsubscribed and resubscribed, get conflicts. Can we get the adjustment?
Brent Zundel: option when you are importing by URL if subscribing to W3C calendar to not include cancelled events, my calendar hasn't quite figured out what is going on, but in theory, if you do that, cancelled things won't show up
Ivan Herman: the way I found it a while ago, go to your own calendar page, go to very end, then it will give you an ICS link with feature. checkbox is new
Joe Andrieu: i bet this will work
Brent Zundel: GDC is in a couple weeks, quite a few members of working group will be there, W3C official organizer. Opportunities to talk with governments and organizations looking to modernize digital identity infrastructure, both corporate and personal. If people from this group are going and would like to coordinate, please reach out...
… signal group called GDC Standards Track, I can add you to the group. and we are at time, so we will talk about TPAC and Threat Modeling next time
<Ted Thibodeau Jr.> fwiw, command-down gets you *straight* to the bottom of `my calendar` page
Brent Zundel: grateful to scribes, and to all the work being done in task forces, moving forward quite efficiently and it is great to see