- From: Pfaff, Oliver <oliver.pfaff@siemens.com>
- Date: Thu, 2 Jul 2015 07:15:19 +0000
- To: "james.lynn@hp.com" <james.lynn@hp.com>, "public-wot-ig@w3.org" <public-wot-ig@w3.org>
- Message-ID: <B842481327FC5344B501EC1921E8538E0132BD43@DEFTHW99EL2MSX.ww902.siemens.net>
Good point James, thanks! I suggest to split the landscape of security&privacy mechanisms for WoT into: - 'Creation time' mechanisms: surveying/suggesting mechanisms and means which help to build and realize the security&privacy architecture of a WoT solution/project/product - 'Execution time' mechanisms: surveying/suggesting mechanisms and means which help to understand the security&privacy status of a WoT solution/project/product and keep it sane This wording is preliminary and would refer to subpages underneath https://www.w3.org/WoT/IG/wiki/Security%26Privacy_Mechanism_Candidates: - 'Creation time' mechanisms: the current contents of this Web page move here - 'Execution time' mechanisms: new, additional content along the lines of your suggestion. I'd appreciate if you would be willing to take the lead for this part! That's meant as upfront info. We should discuss details in the conf call Kind regards, Oliver Von: Lynn, James (Fortify on Demand) [mailto:james.lynn@hp.com] Gesendet: Mittwoch, 1. Juli 2015 18:12 An: Pfaff, Oliver; public-wot-ig@w3.org Betreff: RE: [IG-SP] Conf call on Thurs, July 02 Oliver I would like to request the addition of the following to the agenda: Reference to OWASP Top Ten and other existing projects related to WoT security By definition, the Web of Things is not a closed system. Therefore, it seems prudent to address threat surfaces at various levels or from different perspectives. One such example is the set of OWASP Top Ten projects: https://www.owasp.org/index.php/OWASP_Internet_of_Things_Top_Ten_Project https://www.owasp.org/index.php/Mobile_Top_10_2012 https://www.owasp.org/index.php/Top10 I don't believe we need to do much work along these lines, simply reference and align with them. Regards, J Lynn From: Pfaff, Oliver [mailto:oliver.pfaff@siemens.com] Sent: Tuesday, June 30, 2015 12:02 PM To: public-wot-ig@w3.org<mailto:public-wot-ig@w3.org> Subject: [IG-SP] Conf call on Thurs, July 02 Dear colleagues, our next conf call is scheduled for July 2nd, 16:00 - 17:00 UTC / 18:00 - 19:00 CEST / 09:00 - 10:00 PDT / 01:00 - 02:00 JST Proposed agenda (of course open for your suggestions): 1) Housekeeping 2) Discussion of tech landscape https://www.w3.org/WoT/IG/wiki/Security%26Privacy_Mechanism_Candidates 3) Brainstorming on requirements https://www.w3.org/WoT/IG/wiki/Security%26Privacy_Requirements_Catalogue 4) AOB - Joint workshop with IRTF in Prague, July 12/19 (see https://www.w3.org/WoT/IG/wiki/Joint_IRTF_T2T_RG_/_W3C_WoT_IG_meeting_18-19_July_2015_in_Prague,_Czech_Republic) -Topics for the WoT IG F2F in Sunnyvale (see https://www.w3.org/WoT/IG/wiki/F2F_meeting_29-31_July_2015_in_Sunnyvale_CA#Agenda) Call-in details: WoT Security & Privacy Thursday, July 2, 2015 6:00 pm | Europe Summer Time (Berlin, GMT+02:00) | 1 hr Join WebEx meeting<https://mit.webex.com/mit/j.php?MTID=m987d6b6cf6ce312777c9f2a12656d691> Meeting number: 310 166 494 Meeting password: woft Join by phone +1-617-324-0000 US Toll Number Access code: 310 166 494 Mobile Auto Dial:+1-617-324-0000,,,310166494# Add this meeting<https://mit.webex.com/mit/j.php?MTID=mcfd4aa39f2eef470274d57fb50be22be> to your calendar. Best regards, Oliver
Received on Thursday, 2 July 2015 07:15:57 UTC