Meeting minutes
Brent Zundel: welcome.
… we follow code of conduct, IPR, and policies of W3C.
… Please join if you haven't.
… Today is task force updates, then PR for VCDM, a meeting to plan a meeting, and then moving CID to DID WG
Ivan Herman: just a short thing to say.
… Last week we made a resolution for threat models
… It has been accepted
… Transition is approved
… So, Manu Sporny, I think the onus is on you to get it into the first batch.
Manu Sporny: you mean manually create FPWDs?
Ivan Herman: yes, exactly.
Manu Sporny: will do, but will take time
Ivan Herman: that's ok. Not a hurry, but we need to do it.
Brent Zundel: anyone want to help Manu Sporny?
Manu Sporny: I like that plan.
… I'll do the spec I'm editing. Other editors will do those others.
Ivan Herman: but we need a date
Manu Sporny: we do it when its ready
… editors should just prep it
Ivan Herman: I'm the one who has to process all of these. One a day would not be great.
Manu Sporny: let's move through it, but we don't want to bottleneck for everyone
Joe Andrieu: Just want to clarify - we're talking about an FPWD for each of the threat models and we'll need a snapshot now and then all of them are just NOTEs, from that point forward, Echidna, and running live?
Ivan Herman: that's the only painful thing. Once they are published, echidna kicks in.
Joe Andrieu: To be clear, there is not another set of gates we have to go through?
Antony Mott: I'm willing to volunteer. I'm new. Only done one PR, but I know how much work that could be.
… Caveat: I'll need guidance
Manu Sporny: yes. Thank you, Antony Mott. I'm happy to try and help
… I suggest doing the data integrity one
… this will take a bit longer, but it will be worth it
Joe Andrieu: I am nodding yes, we'll get an FPWD for our threat model as soon as we can, we're not as far along, but we can take on that task.
Brent Zundel: great, Manu Sporny, hopefully you can take that on
… and share the misery
… back to agenda: task force updates
Wesley Smith: update for bar code and data integrity. progress is good. next week FPWD for one of them.
… also a potential action for this group.
… a dark web site recently was found with millions of drivers' license data.
Wesley Smith: this is a great use case context for why VC barcodes is awesome (because of revocation feature)
<Carolynn Bernier> p+
Wesley Smith: Maybe we write a blog post to explain how VC Barcodes could help.
… Question to the group: is this something we want to engage with?
Manu Sporny: other things to consider: does the group say something, does the W3C say something, does W3C put out a press release?
Wesley Smith: also, whether or not that blog post explicitly liases with similar work in other standards groups
Brent Zundel: as chair, blog post makes sense
… overhead may well be worth it
… and if we don't get there, individuals can always leverage the work
Joe Andrieu: The confidence method group pulled in some edits to establish cryptographic confidence methods - based on DIDs or embedded keys.
… We still have a few edge issues to clean up.
… We have started on our diagram for a joint threat model.
… We need to figure out the evaluation part of the process, which may include things like liveness checks.
… I am confident we will get to readiness for FPWD of the threat model in a couple weeks.
Carolynn Bernier: I just meant to say I'm present, but while I'm on the queue. a few words on the dpp task force
… we are working on a relatively complex example for real world entities, with multiple trust anchors
… cleaning up diagram, a bit complicated about who recognizes whom.
… That will be presented to the recognized entity task force and we'll together decide if we want to make it a full blown example
Manu Sporny: that's great, Carolynn Bernier.
… I'm the one that queued you accidentally. (sorry)
… RE work items, we have a privacy review on Render Method. No concerns
… on Recognized Entity spec, internationaltion is done.
… we did get a security review back. It's pretty significant, asking for substantial structural changes
w3c/
Manu Sporny: I'd like to figure out how we are going to format things. Simone is asking to change. We discussed yesterday, but I'm hesitant to rewrite Will Abramson until the group can figure out what we want to do
… that link is the horizontal review. it is thorough, which is good. Seems partially AI generated, which means there is lot of content to review.
… It is specific about the changes desired. I'm not happy about the extra work that is proposed here.
… It feels like 60% of the time is involved in threat models
Wesley Smith: I have questions back to blog post press release
… as of today, I have a draft of language that might form the basis of such a post
… what can we do on the call today to advance this?
… and (b) is this something that edits need group review and final sign off
… or is there a more streamlined option?
… There is time sensitivity to thist.
… Other SDOs are meeting to discuss the future of security of physical documents in the next few weeks.
Ivan Herman: what I want to add is that we should not forget that the plan is go through the W3C blog, which means the communications team has to look at it.
… That shouldn't be a problem, but it will take time
<Carolynn Bernier> About the note in the zoom chat by Antony Mott Mott about the IEEE activity on DPP, I am aware of this work.
Ivan Herman: Another thing, about the text itself, I believe that the solution we are proposing is not only the barcode spec, it's also the bitstring spec.
… maybe we could also mention the forgery defense spec.
… not just on one spec, but on several
… which implicitly supports the family of specs addressing the problem
Brent Zundel: my suggestion is that Wes, you share the draft on the mailing list. Give the group 1 week for comments and suggestions. Next week we'll ask if anyone objects to passing on to coms.
… does that sound reasonable?
Wesley Smith: Yes, that sounds great. What mailing address should I use?
Carolynn Bernier: I wanted to reply to Antony Mott, with a zoom chat comment.
… you talked about two things: the incident (the topic of the blog post) but you also mentioned IEEE product passport work
… related to IEEE work. We are aware of this activity. It's led by Chinese, very different than what we are doing, which is VC based and vocabulary based.
… There are dozens of such efforts around the world
Ivan Herman: maybe to speed up blog process. maybe its worth contacting Coralie now and let her know what we are working on. a summary a sentence or two
… that might speed up processing
Brent Zundel: sounds like a good idea, can you take that action item?
Ivan Herman: it should be one of the chairs.
Brent Zundel: Ok. I'll take it on. If I can get a two sentence summary.
Wesley Smith: ok, will send out later today
Antony Mott: my friend is fascinated by what we're doing at W3C related to IEEE.
… what's interesting is that over there its behind a locked paywall.
… people are confused about which items can be revoked, etc.
<Carolynn Bernier> Yes, many locked paywall SDOs...
Antony Mott: Is it useful perhaps to send this blog post to someone at the IEEE?
… He said he could help spread the word at IEEE. Just offering to connect
VCDM PR
<Carolynn Bernier> I had a meeting today with the IEEE main authors of that standard.
<Carolynn Bernier> Antony Mott, you can share the link to the DPP vocab task force https://
w3c/vc-data-model#1645
Brent Zundel: We have a pull request
… it's rephrasing things (non-normatively)
… the change is the result of a lot of conversation.
… This change is likely to happen, and you all should look at it.
… we could take a comment or two now, but also great if we don't in the interest of time
Joint meeting planning
Brent Zundel: we have a joint meeting scheduled during TPAC with the payment security interest group, on Tuesday
… there is a meeting next week to plan that meeting at TPAC. Everyone in this group should have an invite to that planning meeting
… Next Tuesday 22 at noon ET.
… If that isn't showing up on your calendar and you want to be there, let me know.
… folks from federated identity space, FedId folks. This is an opportunity to continue to insist that the VCDM as an exisiting web standard is viable for digital credentials
… If anyone has any questions or comments, please jump on q
Phil Archer: I'm a bit out of touch, but I'm delighted to hear progress.
… last week, Brent Zundel reflected on experiences at GDC, so I won't repeat that. (I was also there)
… To me, this meeting at TPAC on Tuesday is an occasion where, as astonishing as it may seem, we need to set the record straight within our own standards body that what information is being given is wrong.
… and we need to ask them to stop repeating incorrect information and start acting like we are part of the same organization
Phil Archer: respect for work done is vital
Manu Sporny: +1 to all that.
<Antony Mott> Carolynn Bernier, thank you, I'll share that link.
Manu Sporny: We, as a working group, do need to become more active in helping W3C management in how to relate to other groups
Brent Zundel: definitely will add you Manu Sporny to the Tuesday next call.
<Ted Thibodeau Jr.> Brent Zundel -- link to the meeting that's being planned?
Brent Zundel: please join if you have strong thoughts about what the TPAC meeting should be
… we have been invited to share our voices
Ted Thibodeau Jr.: I don't feel strongly, but I'd like to confirm that I see it on my calendar.
Brent Zundel: the TPAC meeting?
… if you don't see it on your TPAC schedule and look at Tuesday, then indicate that you are planning to attend (it should be bolded because you are a member).
Ted Thibodeau Jr.: is there a link that can help me or do I have to go do that research?
Manu Sporny: there's no easy link to drop in
Brent Zundel: [navigates the w3.org site to see what he might find]
… I see a bunch of joint meetings on 27th of October at 13:15 GMT.
<Ted Thibodeau Jr.> https://
Brent Zundel: if you don't see that, you'll want to adjust your reservation at w3c event site
Ted Thibodeau Jr.: is this the meeting?
Brent Zundel: yes.
… so if you click on that link and are not shown as a participant, you want to go fix that.
Moving CID to DID WG?
Brent Zundel: next up: CID spec movement to DID WG
Brent Zundel: might be a PR on the DID WG draft charter, which would include the CID specification within the work items of the DID WG which would effectively remove it from our puurview
Manu Sporny: I think I pasted the right link.
… +1 to doing this. I think the spec belongs to the DID WG. We caught it because the DID WG prevented that.
… A lot of the content of that spec was actually written by the DID WG.
… It is true what our group depends on the CID spec, but as is being discussed, I believe we have mitigated most concerns
… the expectation is that VCWG can continue to work on it.
… when the new charter activates, the DID WG would be able to take it over
… The charter includes liason roles that will help ensure a smooth transition
… +1 this is a good move. Reduces our work. The DID WG which contains many members of this group, and their are quite capable
<Will Abramson> +1 to moving this across to DID WG when it makes sense
Brent Zundel: thanks for clarification. my main question is: we have two pull requests open on CID right now.
… one is fixing something clearly in scope. The other one is class 3 changes. Does the DID WG want to do more than maintaining? I want to consider that?
… So v2 might be appropriate. Is that on the table?
Manu Sporny: I think that's an excellent question
… expectation is its just maintenance mode
… no class 3 changes allowed unless there are changes
Will Abramson: just to echo Manu Sporny. The DID WG is looking to go into maintenance mode, but if we move the CID spec, then we can have it picked up for work in a future charter
Ivan Herman: I'm looking at the charter, if we do that, then the charter should also give the details of the CID in the deliverables section
Brent Zundel: thanks, Joe.
Ivan Herman: its always possible in the charter to say we are just maintaining, but the security clause is fairly enabling,
… so we might want to think about nuanced language for maintenance
… for example, what happens if new entries in the table are required? That would not be allowed under the current draft.
Manu Sporny: to that point, Ivan Herman, I put a change to the charter that would allow the group to restructure the work, and possibly convert to a registry, which would enable updating the document to become a registry
… we could also put in the charter to say we are going to work on that PR
<Dave Longley> +1 to ensure that maintenance allows the CID spec to incorporate new table entries for multikeys (one way or another)
<Dave Longley> (as pulled from data integrity cryptosuites / other related specs)
Manu Sporny: Let me come down on the side of "mostly maintenance" because the rest of the DID WG is in maintenance, and having that aligned would be preferable. if we want to do class 3/4 we should be specific. we can recharter later on.
… I just don't think we have the bandwidth to run a class 3/4 DID WG in the next 6-9 months
Brent Zundel: I appreciate that. Take my suggestion as a "yes, and" . So, yes, let's transition. Either way its a good thing
Brent Zundel: with that, we are through the agenda.
… thank you all.
… Thanks to Joe and those that joined us for the first time.
scribe out