[{"author": "Mohit Sethi", "text": "<p>KAOS = Knowledge Acquisition in autOmated Specification ??</p>", "time": "2025-04-03T15:01:29Z"}, {"author": "Marco Tiloca", "text": "<p><a href=\"https://notes.ietf.org/notes-ietf-interim-2025-t2trg-03-t2trg?edit\">https://notes.ietf.org/notes-ietf-interim-2025-t2trg-03-t2trg?edit</a></p>", "time": "2025-04-03T15:03:59Z"}, {"author": "Carsten Bormann", "text": "<p>(and that's what the \"Thing-to-Thing\" in T2TRG is...)</p>", "time": "2025-04-03T15:11:09Z"}, {"author": "Michael Richardson", "text": "<p>Hello. Arrived.</p>", "time": "2025-04-03T15:11:45Z"}, {"author": "Ari Ker\u00e4nen", "text": "<p>Welcome!</p>", "time": "2025-04-03T15:11:59Z"}, {"author": "Michael Richardson", "text": "<p>KAOS is a really netflix telling of Orpheus.</p>", "time": "2025-04-03T15:12:33Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>Sadly, yes. Let's change reality and do real T2T :-)</p>", "time": "2025-04-03T15:12:38Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>(ad \"sad state of reality\")</p>", "time": "2025-04-03T15:12:55Z"}, {"author": "Mohit Sethi", "text": "<p>While I can't say about of software evolvability with useful features in general, at least EU regulation now mandates manufacturers to provide several years or more of security patches. From the EU CRA: \"The support period for which the manufacturer ensures the effective handling of vulnerabilities should be no less than five years ...... manufacturers should accordingly ensure longer support period\"</p>", "time": "2025-04-03T15:19:03Z"}, {"author": "Mohit Sethi", "text": "<p>How would webassembly compare with using podman style containerization on esp32?</p>", "time": "2025-04-03T15:20:33Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>It's way smaller. podman is running a Linux userspace. WASM in essence runs a single function; averaging can be like 100 byte of executables.</p>", "time": "2025-04-03T15:21:15Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>And podman has \"everything Linux does\" as its surface, this has just touches messages without the need to provide some filesystem or something like that.</p>", "time": "2025-04-03T15:23:23Z"}, {"author": "Mohit Sethi", "text": "<p>Thanks Christian. Thank you Karolina for the very interesting presentation.</p>", "time": "2025-04-03T15:23:24Z"}, {"author": "Mohit Sethi", "text": "<p>how are webassembly containers signed/verified?</p>", "time": "2025-04-03T15:26:08Z"}, {"author": "Carsten Bormann", "text": "<p>Mohit: We could look into how to use SUIT for this</p>", "time": "2025-04-03T15:26:47Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>Ha! Ha! It was <em>not</em> me who put Rust in here :-D</p>", "time": "2025-04-03T15:29:42Z"}, {"author": "Mohit Sethi", "text": "<p>From Mircrosoft: <a href=\"https://opensource.microsoft.com/blog/2024/09/25/distributing-webassembly-components-using-oci-registries/\">https://opensource.microsoft.com/blog/2024/09/25/distributing-webassembly-components-using-oci-registries/</a>, seems \"Since Wasm Artifacts follow the OCI 1.1 specification, you are not limited to GitHub Container Registry. You can use any of your existing registries and also use investments you\u2019ve made into image signing and software bill of materials (SBOM) support.\"</p>", "time": "2025-04-03T15:29:51Z"}, {"author": "Michael Richardson", "text": "<p>What I see is that we ought to be moving toward a kind of standard WASM runtime system.  (Like RIOT-OS or Aeris)... would have secure/measured boot, firmware updates, onboarding and network security.  It would perhaps even be reviewed by government layer regulator.   Then, then actual algorithms, which are really 5% of the needed code space, are WASM loads.</p>", "time": "2025-04-03T15:29:51Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>I agree that SUIT makes sense there (at least for some functions), but I'm not sure regulatory and signing is a thing there, I'd view them more as configuration made executable.</p>", "time": "2025-04-03T15:32:39Z"}, {"author": "Karol\u00edna Sk\u0159iv\u00e1nkov\u00e1", "text": "<p>Hi Mohit, there is currently no default verification for WebAssembly containers, but we plan to implement verification and authorization for containers as part of the device platform - very good question given we want to enable a multi-stakeholder environment.</p>", "time": "2025-04-03T15:32:44Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>Karolina: <a href=\"https://inria.hal.science/hal-03888109v1\">https://inria.hal.science/hal-03888109v1</a> (Koen is active with me in RIOT OS and Ariel OS)</p>", "time": "2025-04-03T15:34:09Z"}, {"author": "Karol\u00edna Sk\u0159iv\u00e1nkov\u00e1", "text": "<p>Thank you!</p>", "time": "2025-04-03T15:35:23Z"}, {"author": "Michael Richardson", "text": "<p>I'm not saying government should write the code, but rather that they are a useful and involved sober review of code.  Their opinion matters when it comes to devices deployed for public safety.</p>", "time": "2025-04-03T15:36:57Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>Also, Chrystel talked during the RIOT summit about suitable containers; links:<br>\n<a href=\"https://summit.riot-os.org/2023/blog/speakers/chrystel-gaber/\">https://summit.riot-os.org/2023/blog/speakers/chrystel-gaber/</a><br>\n<a href=\"http://summit.riot-os.org/2023/wp-content/uploads/sites/18/2023/09/gaber.pdf\">http://summit.riot-os.org/2023/wp-content/uploads/sites/18/2023/09/gaber.pdf</a><br>\n<a href=\"https://youtu.be/b3436VhisUU\">https://youtu.be/b3436VhisUU</a></p>\n<div class=\"youtube-video message_inline_image\"><a data-id=\"b3436VhisUU\" href=\"https://youtu.be/b3436VhisUU\"><img src=\"https://zulip.ietf.org/external_content/b5573d1adb6d24c83123737776b14a5c0de8b846/68747470733a2f2f692e7974696d672e636f6d2f76692f62333433365668697355552f64656661756c742e6a7067\"></a></div>", "time": "2025-04-03T15:37:28Z"}, {"author": "Mohit Sethi", "text": "<p>What does individual evidence from each router on path contain?</p>", "time": "2025-04-03T15:40:48Z"}, {"author": "Michael Richardson", "text": "<p><span class=\"user-mention silent\" data-user-id=\"2798\">Mohit Sethi</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161008\">said</a>:</p>\n<blockquote>\n<p>What does individual evidence from each router on path contain?</p>\n</blockquote>\n<p>Hi.  Are you speaking about NASR here?</p>", "time": "2025-04-03T15:41:40Z"}, {"author": "Mohit Sethi", "text": "<p>Anyone know if this selective disclosure will be supported by European Digital Identity Wallet? Apparently all driving licenses are becoming digital in the wallet?</p>", "time": "2025-04-03T15:42:02Z"}, {"author": "Mohit Sethi", "text": "<p><span class=\"user-mention silent\" data-user-id=\"169\">Michael Richardson</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161009\">said</a>:</p>\n<blockquote>\n<p><span class=\"user-mention silent\" data-user-id=\"2798\">Mohit Sethi</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161008\">said</a>:</p>\n<blockquote>\n<p>What does individual evidence from each router on path contain?</p>\n</blockquote>\n<p>Hi.  Are you speaking about NASR here?</p>\n</blockquote>\n<p>Yes.</p>", "time": "2025-04-03T15:42:46Z"}, {"author": "Karol\u00edna Sk\u0159iv\u00e1nkov\u00e1", "text": "<p>Practically, will the government ever have the capability for such review without unduly stalling deployments? I would say that assigning responsibility over safety of (especially) cyberphysical systems to motivate all participating actors makes more sense.</p>", "time": "2025-04-03T15:42:52Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>AIU selective disclosure is what they intend to do, but there's some aspect to it where they require that the holder is running in a secure element.</p>", "time": "2025-04-03T15:42:55Z"}, {"author": "Michael Richardson", "text": "<p><span class=\"user-mention silent\" data-user-id=\"2798\">Mohit Sethi</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161010\">said</a>:</p>\n<blockquote>\n<p>Anyone know if this selective disclosure will be supported by European Digital Identity Wallet? Apparently all driving licenses are becoming digital in the wallet?</p>\n</blockquote>\n<p>SD-JWT is already a thing, SD-CWT is what SPICE is doing.  SD-CWT is kinda nicer in many ways.  I expect wallets will grow... I have many questions about who is going to do the maintenance of wallets (layer-9 questions)</p>", "time": "2025-04-03T15:43:14Z"}, {"author": "Michael Richardson", "text": "<p><span class=\"user-mention silent\" data-user-id=\"5824\">Karol\u00edna Sk\u0159iv\u00e1nkov\u00e1</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161012\">said</a>:</p>\n<blockquote>\n<p>Practically, will the government ever have the capability for such review without unduly stalling deployments? I would say that assigning responsibility over safety of (especially) cyberphysical systems to motivate all participating actors makes more sense.</p>\n</blockquote>\n<p>The point is to have platforms that last for decades, even though the actual application of the contents would be unstalled.</p>", "time": "2025-04-03T15:44:29Z"}, {"author": "Mohit Sethi", "text": "<p>From: <a href=\"https://www.consilium.europa.eu/en/press/press-releases/2025/03/25/council-and-parliament-strike-provisional-agreement-on-new-rules-for-driving-licences/\">https://www.consilium.europa.eu/en/press/press-releases/2025/03/25/council-and-parliament-strike-provisional-agreement-on-new-rules-for-driving-licences/</a> \"...by the end of 2030, a uniform mobile driving licence will be available for all EU citizens, placed in the future European Digital Identity Wallet...\"</p>", "time": "2025-04-03T15:44:55Z"}, {"author": "Michael Richardson", "text": "<p><span class=\"user-mention silent\" data-user-id=\"2798\">Mohit Sethi</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161011\">said</a>:</p>\n<blockquote>\n<p><span class=\"user-mention silent\" data-user-id=\"169\">Michael Richardson</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161009\">said</a>:</p>\n<blockquote>\n<p><span class=\"user-mention silent\" data-user-id=\"2798\">Mohit Sethi</span> <a href=\"#narrow/stream/293-t2trg/topic/ietf-interim/near/161008\">said</a>:</p>\n<blockquote>\n<p>What does individual evidence from each router on path contain?</p>\n</blockquote>\n<p>Hi.  Are you speaking about NASR here?</p>\n</blockquote>\n<p>Yes.</p>\n</blockquote>\n<p>NASR requires two layers of remote attestation; the individual evidence from the routers needs to be collected by the ISP, and then (probably via SD-CWT!) turned into new Evidence for another layer of remote attestation, where the ISP provides evidence or Attestation Results to the customer.  It does not make sense for end-customers to attempt to evaluate evidence from routers directly.</p>", "time": "2025-04-03T15:46:13Z"}, {"author": "Carsten Bormann", "text": "<p>Yes, this brings out the difference between attestation and assessment</p>", "time": "2025-04-03T15:47:58Z"}, {"author": "Michael Richardson", "text": "<p>Mohit, please schedule some design team meetings to help progress more text.</p>", "time": "2025-04-03T15:59:39Z"}, {"author": "Mohit Sethi", "text": "<p>Thanks Carsten for the very nice overview. Very useful for somehow like me who missed the IETF.</p>", "time": "2025-04-03T16:01:05Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>Karolina: My colleagues on the Ariel OS chat just corrected my previous link, <a href=\"https://dl.acm.org/doi/pdf/10.1145/3528535.3565242\">https://dl.acm.org/doi/pdf/10.1145/3528535.3565242</a> is the official Femtocontainer paper link.</p>", "time": "2025-04-03T16:01:43Z"}, {"author": "Karol\u00edna Sk\u0159iv\u00e1nkov\u00e1", "text": "<p>Thank you Christian!</p>", "time": "2025-04-03T16:02:06Z"}, {"author": "Christian Ams\u00fcss", "text": "<p>MCR: I like your level of whimsy. Also, to answer the question behind you, chocolate.</p>", "time": "2025-04-03T16:06:43Z"}, {"author": "Carsten Bormann", "text": "<p>And Broccoli!</p>", "time": "2025-04-03T16:06:58Z"}, {"author": "Carsten Bormann", "text": "<p>There they could drill a safe!</p>", "time": "2025-04-03T16:10:44Z"}, {"author": "Mohit Sethi", "text": "<p>yes. interesting problem to work on in general.</p>", "time": "2025-04-03T16:18:00Z"}, {"author": "Carsten Bormann", "text": "<p>(On Mars)</p>", "time": "2025-04-03T16:23:37Z"}, {"author": "Mohit Sethi", "text": "<p>Per <a href=\"https://aws.amazon.com/blogs/security/how-to-use-aws-private-certificate-authority-short-lived-certificate-mode/?utm_source=chatgpt.com\">https://aws.amazon.com/blogs/security/how-to-use-aws-private-certificate-authority-short-lived-certificate-mode/?utm_source=chatgpt.com</a></p>\n<p>price per certificate $0.75 USD for 1-1000 certificates and less if more certificates</p>", "time": "2025-04-03T16:24:45Z"}, {"author": "Mohit Sethi", "text": "<p>yes. the private CA itself costs 400.</p>", "time": "2025-04-03T16:25:11Z"}]