Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PING Horizontal Review #291

Closed
2 tasks done
brentzundel opened this issue May 22, 2020 · 21 comments
Closed
2 tasks done

PING Horizontal Review #291

brentzundel opened this issue May 22, 2020 · 21 comments
Assignees

Comments

@brentzundel
Copy link
Member

brentzundel commented May 22, 2020

@brentzundel
Copy link
Member Author

@jonathan-consensysHealth volunteered to fill out the questionairre

@jonnycrunch
Copy link
Contributor

Will forward to my friend and colleague @jonathan-consensysHealth. Would someone please forward me the submission from the VC working group. Also, I'll need help with the threat model section.

@wyc
Copy link
Contributor

wyc commented Jul 14, 2020

@agropper and myself have volunteered to help draft the responses

@agropper
Copy link
Contributor

agropper commented Aug 10, 2020 via email

@wyc
Copy link
Contributor

wyc commented Aug 12, 2020

@agropper @jonnycrunch due to the time passed, would you like to reconvene later this week or early next week in an open-to-did-wg/public meeting and prepare a working item for comments? hopefully there has been some progress on the service endpoint discussions

@jonnycrunch
Copy link
Contributor

yep, how is Monday again? I'll send an invite.

@wyc
Copy link
Contributor

wyc commented Aug 12, 2020

+1, probably a good idea to inform the public did wg list after we figure out where/when.

We can use the CCG Jitsi instance here: https://meet.w3c-ccg.org/DIDSecurityPrivacyReview

@agropper
Copy link
Contributor

agropper commented Aug 12, 2020 via email

@brentzundel
Copy link
Member Author

@agropper @wyc @jonathan-consensysHealth what is the status of the security and privacy questionnaire?

@wyc
Copy link
Contributor

wyc commented Aug 26, 2020

@brentzundel and those following, the latest response is here:
https://docs.google.com/document/d/13qLCZcks3OAb2V7GHcrSs8s9drA5OaqEPYPI1knmodc/edit#

My apologies, I think I was supposed to write an update to the list and forgot. We are preparing to begin work on sections 3 and 4, but we there were 2 major concerns around scope that would impact the models in those sections significantly:

  • DID methods can vary wildly in their function, side effects, and privacy implications. To what point do we address this in the response? Based on his comments in the doc, Orie seems to think that we should focus only on the data models described and not delve too far into these.
  • Same concern and question for service endpoints.

@msporny
Copy link
Member

msporny commented Nov 24, 2020

We need to have the Security Questionnaire done for this issue to be closed. We cannot close this issue until PING does a review on the specification.

@OR13 OR13 self-assigned this Nov 25, 2020
@OR13
Copy link
Contributor

OR13 commented Nov 25, 2020

I am adding myself to track contributing to the questionnaire.

@shigeya
Copy link
Contributor

shigeya commented Nov 26, 2020

I added a few changes. Reviewed until 2.16.

@kdenhartog
Copy link
Member

kdenhartog commented Nov 29, 2020

We're getting closer on the security questionaire with sections covering all of the security parts (section 3 - might need additional points added as well but solid set in there already), but it appears that section 4 needs to be added still. Also, who is currently handling editorship of this document so that we can get the comments merged/resolved? If no one has time to do this I'm happy to step in and carry this to the end, but I'll need editor rights to the document.

@OR13 @wyc @agropper @jonnycrunch

@OR13
Copy link
Contributor

OR13 commented Nov 30, 2020

@kdenhartog I added some details, but IMO this needs an editorial merging session, and then we should focus on the weakest parts.

@OR13 OR13 removed their assignment Dec 12, 2020
@OR13
Copy link
Contributor

OR13 commented Dec 12, 2020

I think the first checkbox is done now?

@brentzundel
Copy link
Member Author

PING has been contacted for review.
Leaving this issue open to track horizontal review efforts.

@burnburn
Copy link

PING response of "no blocking issues": https://lists.w3.org/Archives/Public/public-privacy/2021JanMar/0021.html

@agropper
Copy link
Contributor

agropper commented Feb 25, 2021 via email

@brentzundel
Copy link
Member Author

Link to invitation for Security review of Decentralized Identifier Specification v1.0: https://lists.w3.org/Archives/Public/public-web-security/2020Dec/0003.html

No response was received and no issues were raised.

@brentzundel
Copy link
Member Author

Horizontal review is complete, closing

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

10 participants