<div dir="ltr">Thanks for the correction. The notes doc has been updated accordingly.</div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Oct 3, 2016 at 11:27 AM, Hardt, Dick <span dir="ltr"><<a href="mailto:dick@amazon.com" target="_blank">dick@amazon.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div class="m_-5373230693276426231WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:Calibri">Corrections highlighted.
</span><span style="font-size:11.0pt;font-family:Wingdings">J</span><span style="font-size:11.0pt;font-family:Calibri"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:Calibri"><u></u> <u></u></span></p>
<blockquote style="border:none;border-left:solid #b5c4df 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-right:0in"><span class="">
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:Consolas;color:black">On 10/3/16, 10:35 AM, someone claiming to be "Openid-specs-risc on behalf of Adam Dawes" <<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank">openid-specs-risc-bounces@<wbr>lists.openid.net</a>
on behalf of <a href="mailto:adawes@google.com" target="_blank">adawes@google.com</a>> wrote:<u></u><u></u></span></p>
</div>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</span><div><span class="">
<p class="MsoNormal">Notes for today's meeting at: <u></u><u></u></p>
</span><div>
<p class="MsoNormal"><a href="https://docs.google.com/document/d/1XZi2p4A5LXLJD7sysQTg33mCtC_yYgdlwHMnmt-12Gk/edit" target="_blank">https://docs.google.com/<wbr>document/d/<wbr>1XZi2p4A5LXLJD7sysQTg33mCtC_<wbr>yYgdlwHMnmt-12Gk/edit#</a><u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div><span class="">
<p style="margin:0in;margin-bottom:.0001pt"><b><span style="font-size:11.0pt;font-family:Arial;color:black">Oct 3</span></b><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:11.0pt;font-family:Arial;color:black">Attendees: Adam Dawes, Marius Scurtescu, John Bradley, Brad Hill, Dick Hardt, Nat Sakimura, Phil Hunt, Anton Taborszky, Henrik Biering, Dale Olds</span><u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">AI: Adam to nail down timing of F2F. Right now it will be for Friday morning (10 - 3, lunch included). If possible, will move to Thursday afternoon. <u></u><u></u></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Symbol;color:black"><span>·<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:11.0pt;font-family:Arial;color:black">RISC F2F Agenda<u></u><u></u></span></p>
</span><p style="margin-right:0in;margin-bottom:0in;margin-left:1.0in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><span>o</span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Initial RISC event definitions<u></u><u></u></span></p><span class="">
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Wingdings;color:black"><span>§<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Hijacking<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Wingdings;color:black"><span>§<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Session revocation/Change password<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Wingdings;color:black"><span>§<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Token revocation (flavors)<u></u><u></u></span></p>
</span><p style="margin-right:0in;margin-bottom:0in;margin-left:1.0in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><span>o</span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">RP registration
<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Wingdings;color:black"><span>§<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">API<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Wingdings;color:black"><span>§<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Email header<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.0in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><span>o</span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Signal sending transport (API)<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.0in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><span>o</span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">SET proposal alignment<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.0in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><span>o</span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">SET RISC format<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.0in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><span>o</span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Mutual milestones (RISC spec, SET spec, provider implementations)<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:1.0in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:"Courier New";color:black"><span>o</span></span><u></u><span style="font-size:9.5pt;font-family:Arial;color:black">Timing: Tentatively Friday morning and if makes sense,
will move to Thursday afternoon.<u></u><u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Symbol;color:black"><span>·<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:11.0pt;font-family:Arial;color:black">Registration API/SET - Email registration<br>
Dick: No <span style="background:yellow">clear</span> <s><span style="background:yellow">one really sees any
</span></s><span style="background:yellow">advantage</span> of the email header. It is perfectly possible to message the user directly in tandem with the API approach.<span class=""><br>
John: this only provides a little cover that the user received an email. But doesn’t tell whether was really informed or gave consent. Also raises concerns over spying in email.<u></u><u></u></span></span></p>
<p style="margin:0in;margin-bottom:.0001pt;vertical-align:baseline"><span style="font-size:11.0pt;font-family:Arial;color:black"><u></u> <u></u></span></p>
<p style="margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Symbol;color:black"><span>·<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:11.0pt;font-family:Arial;color:black">Registration privacy best practices<span class=""><br>
Dick: Send general notice that new capability to protect you across your favorite apps. Give ability to opt out before it starts to happen.<br>
Phil: Maybe initiate this based on some action from the user- first time a user’s app registers for notifications for the user.<br></span>
Dick: probably scale this up by starting with new users and see if there is any negative reaction to it.
<span style="background:yellow">We would want to be transparent to our users when we roll this out.</span></span></p><div><div class="h5"><br>
Brad: To the extent we (FB) are going to do this, we are just going to do it, based on existing language in our ToS that allows sharing data specifically to prevent fraud and abuse. That will mean we need to have agreements with other providers about limitations
on the use of this data. But that is much easier to do than to get individual user opt-in.<br>
Nat: I talked with WP29 person, and she did not find it problematic either.<u></u><u></u></div></div><p></p><div><div class="h5">
<p style="margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt;vertical-align:baseline">
<u></u><span style="font-size:10.0pt;font-family:Symbol;color:black"><span>·<span style="font:7.0pt "Times New Roman"">
</span></span></span><u></u><span style="font-size:11.0pt;font-family:Arial;color:black">Transport discussion Phil: Rushed to get this ready for the charter. Is a parallel with Netconf, xml-based messaging protocol. Lots of parallels but totally different
stack. Good to check that spec to identify parallel use cases but don’t see any convergence. Next steps: waiting for next telechat (10/13) for SET workgroup. Planning on 1 hour meeting Seoul IETF (mid November). Want specific feedback on mutual registration
to subscribe to feed. Need to figure out key discovery/rotation needs to get solidified. Microsoft wants a simpler more stripped down approach of just http post without more of the resilience. Phil will put together SET and transport talks at IIW and that
will be the primer for everyone for the F2F. <u></u><u></u></span></p>
</div></div></div>
</div>
</div><div><div class="h5">
<div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">On Sun, Oct 2, 2016 at 10:11 PM, Adam Dawes <<a href="mailto:adawes@google.com" target="_blank">adawes@google.com</a>> wrote:<u></u><u></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<p class="MsoNormal">Hi all, <u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Here's the agenda for the call tomorrow:<u></u><u></u></p>
</div>
<div>
<ul type="disc">
<li class="MsoNormal">
RISC F2F Agenda<u></u><u></u></li><li class="MsoNormal">
Registration API/SET - Email registration<u></u><u></u></li><li class="MsoNormal">
Registration privacy best practices<u></u><u></u></li><li class="MsoNormal">
Transport discussion<u></u><u></u></li><li class="MsoNormal">
SET <u></u><u></u></li></ul>
<ul type="disc">
<ul type="circle">
<li class="MsoNormal">
Is there a path to type JWTs? Should we push that?<u></u><u></u></li></ul>
</ul>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><b>Call In Details</b><u></u><u></u></p>
</div>
<div>
<div>
<p class="MsoNormal">1. Please join my meeting.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><a href="https://global.gotomeeting.com/join/576653581" target="_blank">https://global.gotomeeting.<wbr>com/join/576653581</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">2. Use your microphone and speakers (VoIP) - a headset is recommended. Or, call in using your telephone.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">United States: <a href="tel:%2B1%20%28312%29%20757-3119" target="_blank">
+1 (312) 757-3119</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Australia: <a href="tel:%2B61%202%209091%207603" target="_blank">
+61 2 9091 7603</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Austria: +43 (0) 7 2088 0716<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Belgium: +32 (0) 28 08 4372<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Canada: <a href="tel:%2B1%20%28647%29%20497-9380" target="_blank">
+1 (647) 497-9380</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Denmark: +45 (0) 69 91 84 58<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Finland: +358 (0) 931 58 1773<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">France: +33 (0) 170 950 590<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Germany: <a href="tel:%2B49%20%280%29%20692%205736%207300" target="_blank">
+49 (0) 692 5736 7300</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Ireland: +353 (0) 15 133 006<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Italy: +39 0 699 26 68 65<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Netherlands: +31 (0) 208 080 759<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">New Zealand: <a href="tel:%2B64%209%20974%209579" target="_blank">
+64 9 974 9579</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Norway: <a href="tel:%2B47%2021%2004%2030%2059" target="_blank">
+47 21 04 30 59</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Spain: <a href="tel:%2B34%20931%2076%201534" target="_blank">
+34 931 76 1534</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Sweden: +46 (0) 852 500 691<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Switzerland: +41 (0) 435 0026 89<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">United Kingdom: <a href="tel:%2B44%20%280%29%2020%203713%205011" target="_blank">
+44 (0) 20 3713 5011</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Access Code: 576-653-581<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Audio PIN: Shown after joining the meeting<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Meeting ID: 576-653-581<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:#888888"><u></u> <u></u></span></p>
</div>
<p class="MsoNormal"><span class="m_-5373230693276426231hoenzb"><span style="color:#888888">-- </span><u></u><u></u></span></p>
<div>
<div>
<div style="margin-top:7.5pt">
<p class="MsoNormal" style="line-height:18.0pt"><span style="font-family:Helvetica;color:#555555;border:solid #d50f25 1.5pt;padding:2.0pt">Adam Dawes |</span><span style="font-family:Helvetica;color:#555555;border:solid #3369e8 1.5pt;padding:2.0pt"> Sr. Product
Manager |</span><span style="font-family:Helvetica;color:#555555;border:solid #009939 1.5pt;padding:2.0pt"> <a href="mailto:adawes@google.com" target="_blank">adawes@google.com</a> |</span><span style="font-family:Helvetica;color:#555555;border:solid #eeb211 1.5pt;padding:2.0pt"> <a href="tel:%2B1%20650-214-2410" target="_blank"><wbr>+1
650-214-2410</a></span><span style="font-family:Helvetica;color:#555555"><u></u><u></u></span></p>
</div>
<p class="MsoNormal"><span style="color:#888888"><u></u> <u></u></span></p>
</div>
</div>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal"><br>
<br clear="all">
<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<p class="MsoNormal">-- <u></u><u></u></p>
<div>
<div>
<div style="margin-top:7.5pt">
<p class="MsoNormal" style="line-height:18.0pt"><span style="font-family:Helvetica;color:#555555;border:solid #d50f25 1.5pt;padding:2.0pt">Adam Dawes |</span><span style="font-family:Helvetica;color:#555555;border:solid #3369e8 1.5pt;padding:2.0pt"> Sr. Product
Manager |</span><span style="font-family:Helvetica;color:#555555;border:solid #009939 1.5pt;padding:2.0pt"> <a href="mailto:adawes@google.com" target="_blank">adawes@google.com</a> |</span><span style="font-family:Helvetica;color:#555555;border:solid #eeb211 1.5pt;padding:2.0pt"> <wbr>+1
<a href="tel:650-214-2410" value="+16502142410" target="_blank">650-214-2410</a></span><span style="font-family:Helvetica;color:#555555"><u></u><u></u></span></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
</div></div></blockquote>
</div>
</div>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div style="line-height:1.5em;padding-top:10px;margin-top:10px;color:rgb(85,85,85);font-family:sans-serif;font-size:small"><span style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(213,15,37);padding-top:2px;margin-top:2px">Adam Dawes |</span><span style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(51,105,232);padding-top:2px;margin-top:2px"> Sr. Product Manager |</span><span style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(0,153,57);padding-top:2px;margin-top:2px"> <a href="mailto:adawes@google.com" target="_blank">adawes@google.com</a> |</span><span style="border-width:2px 0px 0px;border-style:solid;border-color:rgb(238,178,17);padding-top:2px;margin-top:2px"> +1 650-214-2410</span></div><br></div></div>
</div>