Meeting minutes
Brent Zundel: Welcome to today's meeting. Is there anyone who would like to introduce themselves?
… Our agenda today - we will get updates from the task forces, discuss a proposal about publishing a suite of threat models, and do some reporting on the Global Digital Collaboration Process (?)
Task Force Updates
Brent Zundel: If you lead a task force please let us know how it is going. If there are issues or PRs that this group should pay attention to, please let us know.
<Manu Sporny> VCWG Task Force deliverables tracker: https://
Manu Sporny: At a high level, we're doing well from a horizontal review request perspective. We have multiple requests out, for Render Method, VCALM, barcodes, and recognized entities.
… I have a question to the group around when we want to send out the requests for minor version specs.
… Also note feature freezes - not every spec that we requested horizontal review for is at feature freeze right now.
… For recognized entities, we are down to the last set of issues to go into candidate rec. We can put that as a feature at risk - it is trying to address a need from GS1/the supply chain traceability work.
… Isaac has not been able to edit that spec as much as we would prefer. Stephen Curran is a potential editor, who I believe is in the group as an IE.
… Recognized Entities is a couple weeks away from going into CR if we want to go that route. We have only heard back from i18n.
Michael Shea: Is the expectation that controlled identifiers should be going to horizontal review, or is that not appropriate given where it is?
Brent Zundel: the updated version of controlled identifiers should go through horizontal review, but only the diff need to be reviewed, generally.
Ivan Herman: In my recollection, there were no technical changes to that document so far. If there are only editorial changes we may have to notify the horizontal groups but will not have to do anything major.
Michael Shea: What is the deadline for that?
Ivan Herman: Let's table that since it is one of many minor versions.
… My personal take is to postpone that until after the others have gone to CR.
<Kayode Ezike> w3c/
Kayode Ezike: We are in a good place w.r.t horizontal review. Just yesterday, we added a new issue that might be good to discuss. It's relevant to the VCDM spec, where we want to add a new term in the 2.1 context to support BBS and other features.
… Another more general thing is that there are still failures with the deployments - they are not updating when we push to prod. I want to make sure W3C folks are looking behind the scenes, as we are having to use outdated links.
… TR space is still not getting updated when we push to main for our specs.
<Joe Andrieu> w3c/
Joe Andrieu: Two things related to this chart. The feature freeze and threat model should be half. There is some debate on a current PR that could use attention from the group. We have started a threat model - the key trick we are working through is, within confidence method we have different confidence methods and assurance levels.
… Our diagram either needs to address all of it or we need to have multiple diagrams. We are teasing out the best structure here. Our intention is to have the spec text and our submissions for review request in place by TPAC.
Manu Sporny: To respond to Kayode Ezike, I have been able to push things to TR space, so what is broken may be specific to VCALM (or a transient error). We can take it offline.
Wesley Smith: VC Barcodes/ DI update: we are in a fairly good place. Review is requested for barcodes. Still ongoing work for DI, given that there are other related specs in it. Planning to put out review for VC Forgery spec. Doing update for Biststring Status List.
Threat Model publishing
Brent Zundel: Next topic is threat model publishing. Is there more to it than publishing threat models as notes?
Manu Sporny: There is just a bit more. We have to decide what the short names will be as well as publication dates.
Wesley Smith: Is the threat model coupled to the version of the underlying document?
Manu Sporny: They shouldn't be versioned since they are living documents.
Ivan Herman: The note can be a living document that is still bound to a versioned document.
Joe Andrieu: +1 to the framing, but I think we should have versions on the model itself. It is not a registry which is a living document. As soon as the WG goes away we can't edit that document any more. The other thing I wanted to point out as a point of socialization is that, one thing we want to be careful of is imagining there is only one threat model for every spec. There could be multiple documents with different focuses.
… Those tend to want to have different documents and diagrams. We are streamlining a way to publish so that each spec has an easy way to get through the publication process. This is making it easy to get a first version out.
Ivan Herman: is the version in the proposal the version of the document or version of the threat model?
Joe Andrieu: There are two relevant versions - the underlying spec and the threat model
<Wesley Smith> +1 Joe, there are two relevant versions, don't know the best way to express that in a short name.
Manu Sporny: I think threat models should not be versioned, but these things are meant to live more broadly.
… There could be tooling issues with putting versions in the middle of a shortname.
Even if we claim that every version of a spec should have a threat model, I don’t imagine that one spec version would have multiple threat model versions. For this reason, if we MUST add a version to the shortname of the threat model note, I think we can just borrow the same version of the spec.
Joe Andrieu: You've convinced me that having it in the middle is too awkward, but I push back against the idea that threats are for a generic version of the spec. That would make them ungrounded. The value of threat modeling is that it is embodied.
<Manu Sporny> I would suggest that the test suite URL made the wrong decision :)
Brent Zundel: If we update the threat model for the VC data model 2.1, do we just update the threat model?
Joe Andrieu: I think we should version the threat models, I don't know that the versions need to propagate into the shortnames/URLs
<Manu Sporny> Let's not do two versions in a URL. :)
<Manu Sporny> Agree w/ Joe's proposal.
Ivan Herman: +1 to Joe, we can change the title and version number without changing the URL
<Brent Zundel> PROPOSAL: Publish all Threat Models created by the VCWG as NOTEs. The shortnames for the threat models should start with the unversioned shortname of the associated specification, and then "-threat-model", and then "-<VERSION>" (where VERSION is the version of the associated specification). The threat models should be published at the soonest reasonable publication date as determined by Editors, Chairs, W3C Staff, and Management.
<Manu Sporny> +1
<Wesley Smith> +1
<Dave Longley> +1
<Joe Andrieu> +1
<Kayode Ezike> +1
<Phillip Long> +1
<Jennie Meier> +1
<Ivan Herman> +1
<Ted Thibodeau Jr.> +1
<Sebastian Schmittner> +1
<Michael Shea> +1
RESOLUTION: Publish all Threat Models created by the VCWG as NOTEs. The shortnames for the threat models should start with the unversioned shortname of the associated specification, and then "-threat-model", and then "-<VERSION>" (where VERSION is the version of the associated specification). The threat models should be published at the soonest reasonable publication date as determined by Editors, Chairs, W3C Staff, and Management.
Brent Zundel: hearing no objections and seeing nothing but +1s, we are resolved.
Ivan Herman: One request is to send me three URLs for three threat model documents so it's not too abstract.
Global Digital Collaboration Conference (GDC26) Report and Q&A
Brent Zundel: Our last topic is GDC report and Q/A. Last week was Global Digital Collaboration in Geneva and attended by more than 2000 people - which is a 3x increase from last year. This is a conference that attempts to be a little bit of everything digital identity, primarily on the use case side.
… Largely the conference was focused on mDL rollout - there were sessions that talked about ZKPs, age assurance, and identity for AI.
… There was also substantial discussion about trade modernization.
<Ingo Wolf> how was the discussion on SD-JWT vs. JSON-LD based credential formats going - if at all?
Brent Zundel: There was very little conversation about data formats - most presentations just said "Digital Verifiable Credential". Most specifics were around mdoc.
Manu Sporny: What we (Digital Bazaar) are experiencing is that people are moving beyond talking about data formats/protocols - there is an expectation that everyone will support everything. That is at least our experience in North America.
… I'm curious what W3C said as an organizer? I know PA was there, I think I saw a picture of Dom on stage - I'm curious to hear what W3C was saying. Question 2 is whether there are any actions from the conference.
… Is there anything actionable happening, or is it just yet another identity conference where people talk about latest learnings but without movement on the technical side?
<Brent Zundel> GDC 2026 Book of Proceedings: https://
<Elaine Wooton> i was there - i saw simone talk about age assurance - nothing profound
Brent Zundel: I didn't attend most of the W3C centric sessions, so I wasn't in the room for a lot of that - but much of it was DC API conversations. The W3C took part in some threat modeling Sebastian Schmittnerrcises for age assurance.
<Ted Thibodeau Jr.> Did any attendee notice, was there any distinction drawn between W3C (D)VCs and EU D(V)Cs?
Brent Zundel: As far as what this group should do, one difference that I noticed between (and this is systemic more than anything) W3C vc OIDF - the OIDF was very deliberate in the things that they supported and the sessions they proposed, whereas W3C had things that team members wanted to touch on, but for the most part sessions were left to W3C members to propose.
… There was less top-down-organized "here is how the W3C is going to engage with this conference".
… Next year it may be beneficial for at least our group to say "here is what we want to happen at this conference".
Michael Shea: I wasn't able to attend the GDC this year, but your description sounds spot on. I was there last year. Historically it's very focused on personal identity, but what you are describing sounds very much what I would expect.
Ted Thibodeau Jr.: Wondering if there was a distinction drawn between W3C VCs and the EU's Digital Credentials, which have been blurred a lot over time.
Brent Zundel: For the most part they were not talking about what we are talking about.
<Michael Shea> unless in the trade area.
Ted Thibodeau Jr.: That is problematic, especially given that W3C was one of the organizers.
<Elaine Wooton> my internet went out - of course
<Manu Sporny> I think that's by design Ted :)
<Michael Shea> Manu Sporny +1
Phillip Long: the Swiss Digital ID had some pragmatic discussion previously at the conference.
Manu Sporny: To reflect on what Ted Thibodeau Jr. said - the coopting of the term "Verifiable Credentials" was an intentional choice. The umbrella term appears to be "Digital Verifiable Credentials", which include all the formats.
… There is a group that is trying to dilute what the term Verifiable Credential means.
<Elaine Wooton> I went to the interop Sunday and Monday before GDC at IATA - it's all mDOC - if W3C wants to be seen, there needs to be a way to participate - I don't know what that is - someone from MOSIP came to the one in Bangkok and of course, there was no "interop" for them
Manu Sporny: That said, note that California talks about its digital credential program as "the mDL program" - but most of the credentials they issue are W3C VCs.
<Elaine Wooton> If Credence can read the CA DL then we should show up with that physical document and have it succeed
<Dave Longley> +1 an "mDL" can be (and often is) a W3C Verifiable Credential -- the terminology is quite fluid in the space.
Manu Sporny: Item two is that I am, as a W3C member, displeased with the lack of W3C leadership around the W3C Verifiable Credential work. Leadership is not engaging with opportunities, the messaging is sloppy, and the OIDF is doing an excellent job. I am disappointed with the way W3C has engaged with GDC, and there are many lost opportunities there.
<Ted Thibodeau Jr.> problem is that the two (or more) are not interoperable
<Michael Shea> particularly since they were a sponsor...