Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FDC3 Identity & Threat Modelling - 9 Nov 2023 #1101

Closed
5 tasks
Yannick-Malins opened this issue Nov 9, 2023 · 9 comments
Closed
5 tasks

FDC3 Identity & Threat Modelling - 9 Nov 2023 #1101

Yannick-Malins opened this issue Nov 9, 2023 · 9 comments
Labels

Comments

@Yannick-Malins
Copy link
Contributor

Yannick-Malins commented Nov 9, 2023

Group overview

FDC3 revolves around several types of independent entities:

  • Applications
  • Desktop Agents
  • App Directories
  • Users

Each of these has an identity, and needs to know and trust the identities of several of the others in order to work seamlessly.However, at present there are few or no methods for them to validate those identities within the FDC3 Standard, meaning trust must be assumed. This comes with problems and risks : data loss, identity theft, oauth hell, or an inability to adopt interop via FDC3 - all of which are a threat to the FDC3 ecosystem’s continued growth. This complexity is multiplied by the different types of FDC3 setups now possible - desktop app interop, in-container interop, web interop, and interop between Desktop Agents (Bridging).

Over the past few years, various discussions, demos and roundtables have addressed this topic, but the outcome each time has been “what do our users need?”.

Therefore our first objective in this stream is to dig into what these risks and problems are, before we discuss and work on potential solutions

Relevant issue tags

identity-security

Meeting Date

Thursday 9 Nov 2023 - 11am (US eastern timezone EDT/EST) / 4pm (London, GMT/BST)

Zoom info

  • Join Zoom Meeting
  • Meeting ID: 969 4029 4948
  • Passcode: 636931
  • Dial-in:
    Country International Dial-in Toll-free Dial-in
    US +1 929 205 6099 (New York) 877 853 5247
    UK +44 330 088 5830 0800 031 5717
    France +33 1 8699 5831 0 800 940 415
    Find your local number https://zoom.us/u/ad2WVnBzb8

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

  • A Discussion Group has no direct decision-making power regarding the FDC3 standard - rather it is intended that anything they propose or work on will result in proposals (via Github issues and PRs) for the Standards Working Group participants to consider and vote on for inclusion in the standard.

Agenda

  • Convene & roll call, review meeting notices (5mins)
  • Recap of the previous session (5mins)
  • Discussion of requirements around user identity (15mins)
  • AOB & Adjourn (5mins)

Minutes

  • ...

Action Items

  • ...

Untracked attendees

Full name Affiliation GitHub username
@Yannick-Malins Yannick-Malins added help wanted Extra attention is needed meeting labels Nov 9, 2023
@Yannick-Malins
Copy link
Contributor Author

Yannick-Malins commented Nov 9, 2023

After a first session focused mainly on application and agent identity, this second session will focus on user identity

@bingenito
Copy link
Member

Brian Ingenito / Morgan Stanley

@mattjamieson
Copy link
Contributor

Matt Jamieson / WhiteDog

@kriswest
Copy link
Contributor

kriswest commented Nov 9, 2023

Kris West / Interop.io 🚀

@robmoffat
Copy link
Member

Rob / FINOS 🐟

@hughtroeger
Copy link
Contributor

Hugh Troeger / FactSet

@paulgoldsmith
Copy link

Paul Goldsmith / Morgan Stanley

@kriswest
Copy link
Contributor

Need minutes before closing - perhaps worth trying an AI summarize on recording/transcript?

@bingenito
Copy link
Member

@kriswest This might have to be an update to agreements and reviewed by participants Legal teams. There is currently an assumption that the recordings are private and only for internal use, sending that to a service for summary might require notification and sign-off from all participants.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

7 participants