W3C

Verifiable Credentials Working Group Telco

26 August 2026

Attendees

Present
Antony Mott, Benjamin Young, Brent Zundel, Carolynn Bernier, Dave Longley, Dmitri Zagidulin, Elaine Wooton, Sebastian Schmittner, Hiroyuki Sano, Ivan Herman, Jennie Meier, James Richards, Joe Andrieu, Kayode Ezike, Michael Shea, Phillip Long, Phil Archer, Saad Bin Shams, Ted Thibodeau Jr., Wesley Smith, Will Abramson
Regrets
-
Chair
Brent Zundel
Scribe
Will Abramson, Wesley Smith

Meeting minutes

Brent Zundel: Welcome to VCWG. We follow W3C IPR and other policies.
… First up, agenda review
… We will talk about threat models. How we publish and incorporate those within our specs
… We will be getting task force updates
… Also talking about GDC which is next week. Then TPAC in October
… Before all that intros. ANyone want to introduce themselves?

Antony Mott: Hi I am Anthony, I live in New York. Work with machine learning, multi modal LLM. Passionate about progress and safeguarding the future from both bad actors and negative side of AI
… Heavily into coding etc. Was using a crypto algorithm that was not standardized. Wrote a draft. Got introed to manu and that led me here

Phil Archer: anthony, could you please join IRC.

<Michael Shea> not GS1, but W3C...

<Sebastian Schmittner> https://xkcd.com/1782/

Phil Archer: IRC is how we do things at the W3C. where the minutes are taken etc

Threat Model meta conversation

Brent Zundel: We are talking about how are we going to publish these things, are we even going to, do we need to publish these things. What tools etc
… a meta conversation about how we are dealing with threat models across task forces
… We are strongly encouraged to do these threat models in order to populate our security and privacy considerations
… NOt sure we are required to publish the threat models themselves

Ivan Herman: Let me give an overview of where we are now
… All threat models we have right now are in a separate document. They are on github and can be served on github pages
… The question is what to do with them
… The expectation of the W3C, as far as I know, is to have the threat models published somewhere
… Two irreconcilable positions we could take. We publish each threat model as individual WG notes.
… We are talking about something between 12-15 documents here
… This is a one time big effort
… The other side, is to have the threat model included as part of the specifications themselves
… E.g. to add a new chapter specifications. This is viable alternative, although may need to configure and update echidna and tooling to support this
… Think this is doable
… The tooling used for the creation of threat model document are different from one task force to another. This is a pity
… It would be good to have those aligned
… This tooling has been developed across the various task forces and the DIDWG
… It would be good to have a common approach across WGs
… Manu who developed the tooling and is the editor of many of these documents is unfortunately not here. We should wait for him before final decision

Joe Andrieu: Great summary Ivan Herman
… Wanted to nuance the requirements. SING has requested the threat models be created and published

<Antony Mott> Antony for Ivan Herman and Phil Archer : thanks for the summary

Joe Andrieu: I support this as a direction to help upskill the security layer
… The process itself is still silent on this matter

Joe Andrieu: There is an understanding that threat models should be treated as living documents. Can be updated as we become aware of new threats
… Structurally these feel like they fit more in a W3C registry dynamic
… I am a fan of the camp where we have a separate repo for the threat models
… If we were to move these into W3C registry, having a separate repo makes this easier

Ivan Herman: One process point to be clear. It is correct that if it is part of a recommendation, then updating the threat model requires a WG. This is true for Notes too

Joe Andrieu: Yes, I was talking about the new W3C Registry artifact WGs can create

Brent Zundel: Any other opinions?

<Antony Mott> If the W3C group doesn't have tools, is this helpful (we find them useful!)l: https://owasp.org/www-project-threat-modeling/

Will Abramson: I want to suggest a middle path - I wonder if there is a sensible combination of some of the documents to avoid the high number of documents. In the DID working group we combined threat models into a single threat model for the ecosystem. Maybe there isn't one for this ecosystem, but we could still combine some.

Ivan Herman: Some of this has already happened - for example, the cryptosuites do not have individual threat models, just the DI threat model. On the other hand, binding all of them into one would be a huge document.

Ivan Herman: Some of the threat models already combine and address multiple specs. E.g. the cryptosuite specs
… Combining all threat models into one would make the doc huge and pretty unmanagable

Phil Archer: Slightly concerned that our decisions are being driven by a process that wasnt designed for this and tooling that hasnt been built for this
… Joe Andrieu is right we discover and document new threats all the time. It is something that is dynamic. It is like the errata part of a spec
… I think this is a very good feature. But it suggests that the process and the tooling need to be updated so that we can publish these threat models in a way that actually works for the people doing the work

Antony Mott: Trying to work out how this connects to the OWASP threat modelling approach. Have the group looked into this

Brent Zundel: Anyone have an answer?

Wesley Smith: I don't know a lot of the details of this approach. What is currently happening, is the W3C is currently trialing the new approach from the Security interest group guidance around how to produce threat models
… It feels like the questions around OWASP fit more here
… Today we are talking more about the process of publishing and maintaining threat models within this group

<Ivan Herman> +1 to Wesley Smith

Wesley Smith: Recommend connecting to the SING group to discuss how threat modelling should be done

<Antony Mott> ok: got it, thanks

Wesley Smith: I think the VCWG is one of the first group to do threat modelling following this guidance

Brent Zundel: We have done a good job of outlining where we are at, we have a few suggestions for where we want to go. Does anyone want to propose next steps?

Ivan Herman: I am neutral about how we publish these documents.
… What counts the most is what is comfortable for the people doing the work. This is a huge amount of wokr
… We have a discussion on an email threat about this
… I want to hear manu's opinion because he is the editor of many of these documents. Want something that is comfortable for him

<Antony Mott> Dave Longley: I see, it's the actual logistics (storing publishing) of the docs, then maintaining that juggernaut...huge job and different.

<Dave Longley> +1 Antony Mott

Joe Andrieu: I agree. There is another conversation going on where we are trying to figure this out with staff and SING. Without manu's voice it is hard to believe we have consensus around any options we might pursue
… Think we should revisit this next week

Task Force Updates

Brent Zundel: good foundational conversation. More conversations necessary when other people are in the room

Brent Zundel: If you are leading a task force, please jump on the queue to let us know how things are going

Wesley Smith: Update from the VC barcodes and data integrity task force
… Couple of weeks ago we got call for horizontal review out
… We are working to finalize the features, moving some things out of the spec
… Data integrity is ongoing. Lots of work to improve readability and extract commonality across cryptrosuites
… forgery defense is in a good place. Expect to put out a call for horizonal review for this soon

Carolynn Bernier: In recent vocabulary task force we agree to create a ecosystem example for the recognized entities use case
… We were hoping to model a DPP example with several trust anchors. This would go in Annex B

Kayode Ezike: Here to give an update on VCALM

<Kayode Ezike> interaction provisional IANA URI registration: https://www.iana.org/assignments/uri-schemes/prov/interaction

<Kayode Ezike> web+interaction provisional IANA URI registration: https://www.iana.org/assignments/uri-schemes/prov/web+interaction

<Kayode Ezike> IANA URI schemes: https://www.iana.org/assignments/uri-schemes

Kayode Ezike: We have officially gotten the two IANA schemes registered
… These are provisional URIs at the moment. We hope to mmake them permanent down the line
… Progress on horizontal review. Requested reviews for internationalization and accessiblity. Working towards security and privacy
… Needed to refactor the spec to inline the threat model
… Progress on various issues and PRs

Phil Archer: GS1 hat on. Regarded the recognized entities spec, we are very excited about this
… adjusting our data model to match
… We intend to offer an update and an implementation to the spec

Dmitri Zagidulin: For render method task force. We have started internationalization and accessibility for horizontal reviw
… continue to work through the threat modelling, where we have some naming decisions to make
… On track for the three main render method suites

<Joe Andrieu> w3c/vc-confidence-method#43

Joe Andrieu: PR 43 has active discussion in the group
… Adding DID based authentication methods to confidence method
… A good draft, needs some tweaking
… This thursday we will be starting the groups discussion about threat modelling for this spec
… 7am Pacific

Brent Zundel: Thanks for these updates. Great to see things progressing

GDC, TPAC

Brent Zundel: Global Digital Collaboration hapening next week in Geneva

<Phil Archer> https://globaldigitalcollaboration.org/gdc26?day=sept-1

Brent Zundel: TPAC happening in dublin in October
… W3C is an organizing member of GDC. Lots of people from the team and members of WG will be there

<Carolynn Bernier> I will be at GDC

Brent Zundel: Opening the floor to disucss what the goals should be for this conference. What would you like to see accomplished

Brent Zundel: I will be on a panel on day 3 to talk about holder binding
… Think there will be quite a bit happening on zero knowledge
… A lot about use of VCs in trade

Phil Archer: I am on a panel on day 3. With steve capell an the UN transparency
… I am apprehensive. People may be there advocating strongly for there own work and also dismissing the work from this group
… Hoping the spirit of the event is collaborative
… Three days of flying the flag for the group. What we do and why we do it

<Ted Thibodeau Jr.> What exactly does "holder binding" mean in this context? I don't think it's yet meant the same thing to two speakers...

<Dave Longley> +1 to all the work and flag flying too!

Joe Andrieu: +1 to all the work. Appreciate that folks are going and carrying our conversations forward in this space
… In brussels we had talked about how we might create a registry for all sorts of different vocabularies that can be applied to VCs from around the world
… Rather than having the WG to be those experts. Perhaps we have the WG set up a registry and an interest group form to maintain that registry

<Antony Mott> @Phil Archer + @Carolynn Bernier : thanks for flying flag next week...cannot imagine how anyone could not be anything but open to other people's ideas...that's the point of conferences!

Joe Andrieu: I think this is a good idea. A lot of moving parts to get this going. Encourage folks to use GDC and TPAC to coordinate and move this forward

Carolynn Bernier: wanted to ask Brent Zundel and Phil Archer if there will be a moment to present the status of all the work from this group
… Is there such a presentation planned

Brent Zundel: Do not believe there is one planned with that topic

Phil Archer: Agree it would be great if there were
… I didn't think of that. Not sure what to expect. Need to know in advance that is what you want to do. We didnt.

Ivan Herman: Wondering if Pierre Antoine is planning to do somethinbg around this. He was there last year and did something similar
… Not sure

<Joe Andrieu> https://github.com/WebOfTrustInfo/rwot11-the-hague/blob/master/final-documents/identifier-binding.pdf

Joe Andrieu: Responding to Ted Thibodeau Jr. question about holder binding. Feel that many people in this group have tried to move beyond this phrase
… There was a paper that got written that moved from holder binding and initiated the recognized entity and confidence method work

Brent Zundel: The work we are doing in the VCWG I intend to mention on the panel on holder binding
… more of a Yubico panel than W3C panel

Will Abramson: I'll also be there and am looking forward to it. It was collaborative last year. I'll be flying the flag for DIDs, but also interested to see the different places where these technologies have adoption and interest.
… It's good to hear from people who deal with identity problems but don't have technical backgrounds and often aren't in the same spaces.

<Ted Thibodeau Jr.> Joe Andrieu -- That paper appears to be 3 years old?

<Phil Archer> https://www.w3.org/2026/ecommerce-agents/agenda

Phil Archer: Some people speaking at GDC are going to be staying in Geneva to speak about agentic commerce and AI
… Talking about AI agents and what is there agency. How can users retain control over agents that are spending there money
… There is some overlap here which is interesting
… Thank you Will for saying that it was a collaborative atmosphere

<Joe Andrieu> Ted Thibodeau Jr. -- Yep.

Brent Zundel: I agree it really was a good conference last yeatr
… Would like to shift focus to TPAC
… We have WG meetings scheduled for thursday and friday that week

<Carolynn Bernier> Joe Andrieu I agree that it may be a good place to gather interest around vocabularies.

Brent Zundel: Plus a joint session with payments on the tuesday
… Anything that you think this group should be focused on at TPAC this year
… From the chairs perpsective we are going to be helping people going through horizontal review get to CR. And have conversations that help specs get there

Ivan Herman: For TPAC, if we talk about CR we will also have to talk about testing
… No idea where we are with this, but we will need testing information about new specs
… Do not need the full test suite, but need information about how we plan to handle testing

<Kayode Ezike> Don’t know if this is already on the agenda for TPAC, but we really should get to the bottom of the digestSri vs digestMultibase debate.

<Kayode Ezike> +1 Phil Archer

Phil Archer: We will be discussing the issue of the digestSRI and digestMultibase. We feel this needs f2f time to resolve this
… Tomorrow we will be having a joint session with payments. It is tomorrow at 3pm. They want to discuss what should be discussed in the joiunt session at TPAC
… One more thing. Social time is as important as anything else
… Previous recent TPACs have lacked werewolf games. Fantastic game. Part of the culture. Happy to run games

<Antony Mott> @all (Phil Archer): + to social time...I'm down to play (I'll be at TPAC) and look forward to meeting some of you in person in Dublin!

Brent Zundel: Any other questions or comments
… Note, due to GDC we will not be having a regular WG call next week
… We will meet again in two weeks time

<Ted Thibodeau Jr.> fwiw, I have a long personal dislike of werewolf, and would be unlikely to participate were I attending TPAC.

Brent Zundel: Okay lets close early

<Phil Archer> yay Will Abramson!

Brent Zundel: Fantastic work folks. The Task Force working pattern has been astounding. Very impressive amount of work. Thanks everyone, pleasure working with you

Minutes manually created (not a transcript), formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).