[{"author": "Brendan Moran", "text": "<p><span aria-label=\"wave\" class=\"emoji emoji-1f44b\" role=\"img\" title=\"wave\">:wave:</span></p>", "time": "2024-03-20T03:00:41Z"}, {"author": "Alexey Melnikov", "text": "<p><a href=\"https://notes.ietf.org/notes-ietf-119-iotops\">https://notes.ietf.org/notes-ietf-119-iotops</a></p>", "time": "2024-03-20T03:02:59Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>I'll help with the minutes as well.</p>", "time": "2024-03-20T03:04:02Z"}, {"author": "Alexey Melnikov", "text": "<p>Thank you Christian and Warren</p>", "time": "2024-03-20T03:04:38Z"}, {"author": "A.J. Stein", "text": "<p>So you need reviewers for draft-ietf-iotops-security-summary-01? I guess I can volunteer to force myself to read yet another document by my employer.</p>", "time": "2024-03-20T03:30:16Z"}, {"author": "Alexey Melnikov", "text": "<p>Yes, please!</p>", "time": "2024-03-20T03:34:20Z"}, {"author": "A.J. Stein", "text": "<p><span class=\"user-mention silent\" data-user-id=\"370\">Alexey Melnikov</span> <a href=\"#narrow/stream/233-iotops/topic/ietf-119/near/112906\">said</a>:</p>\n<blockquote>\n<p>Yes, please!</p>\n</blockquote>\n<p>I do not have a lot of familiarity with the document but I need to read and understand the context because I am a little unclear at pointing to NIST 8529A which is basically a standard mapping to other standards more or less, but TBD and that's part of the impending review.</p>", "time": "2024-03-20T03:35:35Z"}, {"author": "A.J. Stein", "text": "<p>Whoa whoa, I never claimed to support intelligent reading.</p>", "time": "2024-03-20T03:39:52Z"}, {"author": "A.J. Stein", "text": "<p>Oh good Alexy assuaged my concerns. <span aria-label=\"smile\" class=\"emoji emoji-1f642\" role=\"img\" title=\"smile\">:smile:</span></p>", "time": "2024-03-20T03:40:05Z"}, {"author": "Brendan Moran", "text": "<p><span aria-label=\"laughing\" class=\"emoji emoji-1f606\" role=\"img\" title=\"laughing\">:laughing:</span></p>", "time": "2024-03-20T03:40:05Z"}, {"author": "Brendan Moran", "text": "<p>The original intent of this draft was a best practices draft for making secure devices. The request was for it to be tilted towards a \"so you want this req, use this draft\" a-la carte menu.</p>", "time": "2024-03-20T03:40:45Z"}, {"author": "Alexey Melnikov", "text": "<p>We (IETF) don't want to promise that the mapping is correct. Certainly not in legal sense.</p>", "time": "2024-03-20T03:43:06Z"}, {"author": "A.J. Stein", "text": "<p>And then we get to the next slide on \"what does the baseline mean?\" and this is exactly the kind of question that gives me hives.</p>", "time": "2024-03-20T03:44:05Z"}, {"author": "A.J. Stein", "text": "<p>There are a few definitions from one of those parties you reference, but I would say of these semi-official defs baseline of control requirements is like a profile of a protocol spec in IETF by analogy (in my NIST experience). Reference, one of the terms in here:</p>\n<p><a href=\"https://csrc.nist.gov/glossary/term/baseline\">https://csrc.nist.gov/glossary/term/baseline</a></p>", "time": "2024-03-20T03:45:39Z"}, {"author": "Ira McDonald", "text": "<p>Tongue-in-cheek - from Palo Alto CSA yesterday <br>\n3/18/2024 <a href=\"https://csa-iot.org/newsroom/the-connectivity-standards-alliance-product-security-working-group-launches-the-iot-device-security-specification-1-0/\">https://csa-iot.org/newsroom/the-connectivity-standards-alliance-product-security-working-group-launches-the-iot-device-security-specification-1-0/</a></p>", "time": "2024-03-20T03:46:22Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>@meetecho, please pivot to speaker</p>", "time": "2024-03-20T03:47:21Z"}, {"author": "Warren Kumari", "text": "<p>As a quick note: Christian is doing all the notes, I'm just getting in the way... :-)</p>", "time": "2024-03-20T03:47:33Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>thx</p>", "time": "2024-03-20T03:47:42Z"}, {"author": "Brendan Moran", "text": "<p>So my specific complaint is that \"baseline\" means it should be a minimum, but all three documents provided only requirements, none of them provided any direction whatsoever on <em>exceeding</em> those requirements. this starts to sound like they are not, in fact, minima, but actually are fixed requirements.</p>", "time": "2024-03-20T03:49:40Z"}, {"author": "Brendan Moran", "text": "<p>I realise that NIST's definition of \"baseline\" does not say that it is a minimum, but the common use in English is \"a minimum or starting point for comparison\" which heavily implies that it should be possible to do better than the baseline.</p>", "time": "2024-03-20T03:54:24Z"}, {"author": "A.J. Stein", "text": "<p><span class=\"user-mention silent\" data-user-id=\"1165\">Brendan Moran</span> <a href=\"#narrow/stream/233-iotops/topic/ietf-119/near/112990\">said</a>:</p>\n<blockquote>\n<p>I realise that NIST's definition of \"baseline\" does not say that it is a minimum, but the common use in English is \"a minimum or starting point for comparison\" which heavily implies that it should be possible to do better than the baseline.</p>\n</blockquote>\n<p>I can completely relate to the problem. I am not sure I have a good metaphor the different profiles represent different respective minimum requirements and baselines. In NIST parlance, I have seen profile and baseline used interchangeably. I will see how I can help you constructively with this in a review. I don't like it or agree with it, but I can acknowledge the fun state of affairs. <span aria-label=\"laughing\" class=\"emoji emoji-1f606\" role=\"img\" title=\"laughing\">:laughing:</span></p>", "time": "2024-03-20T03:59:08Z"}, {"author": "Brendan Moran", "text": "<p>Thank you!</p>", "time": "2024-03-20T04:00:24Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>The \"routers in virtualization tools\" item looks like one well addressable by mDNS proxying for which I think some solutions are around and would only need to be added to the containers.</p>", "time": "2024-03-20T04:06:21Z"}, {"author": "Matthew Gillmore", "text": "<p>+1 at Christian's comment</p>", "time": "2024-03-20T04:07:37Z"}, {"author": "Matthew Gillmore", "text": "<p>+1 to Michaels comment</p>", "time": "2024-03-20T04:10:46Z"}, {"author": "A.J. Stein", "text": "<p>Side note: Carsten: what slide technology are you using with Markdown to facilitate these slide deck pitch to I-D Markdown strategy?</p>", "time": "2024-03-20T04:15:18Z"}, {"author": "Carsten Bormann", "text": "<p>I'm using a commercial tool, <a href=\"http://deckset.com\">deckset.com</a></p>", "time": "2024-03-20T04:15:36Z"}, {"author": "Warren Kumari", "text": "<p>Did Carsten say that the slides were made in Markdown? If so, what?</p>", "time": "2024-03-20T04:15:49Z"}, {"author": "Warren Kumari", "text": "<p>Oh.</p>", "time": "2024-03-20T04:15:51Z"}]