<div dir="ltr">I agree we need to ensure that discussions are scoped to the WG charter. I do think that there is a general protocol and data format aspect to the discussion that may be germain. For example, if we assume that clearinghouse use cases may encompass sending/receiving collections, rather than single events, should we entertain revision to the current data format? However, broader questions such as privacy implications of a clearinghouse model are likely out of scope. Interesting, but out of scope. ;)<div><br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>Cheers,</div><div>=D=</div><div><br></div><div dir="ltr"><font color="#2c5280" face="Arial, sans-serif"><b>---</b></font></div><div dir="ltr"><font color="#2c5280" face="Arial, sans-serif"><b>David Skyberg</b></font><div><font color="#2c5280" face="Arial, sans-serif">Product Director</font></div><div><font color="#2c5280" face="Arial, sans-serif">Capital One Identity Services</font></div><div><font face="Arial, sans-serif" color="#000000">703.439.8876</font><font color="#2c5280" face="Arial, sans-serif"><b><br></b></font></div><div><font face="Arial, sans-serif" color="#000000"><a href="mailto:david.skyberg@capitalone.com" target="_blank">david.skyberg@capitalone.com</a></font></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Dec 5, 2019 at 3:11 PM Richard Backman, Annabelle <<a href="mailto:richanna@amazon.com">richanna@amazon.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div class="gmail-m_-6971326574197881194WordSection1">
<p class="MsoNormal">It should be noted that <a href="https://urldefense.com/v3/__https://openid.net/wg/risc/charter/__;!0Ns9_1dOjwg!L_IHRWDKAjugqfAYNWdNwfIR4zRqmSXC6S-RacX8K66DGod-tTnqQ9Ml6_PayDE77Q5MnaQ$" target="_blank">
the current charter</a> and <a href="https://urldefense.com/v3/__https://bitbucket.org/openid/risc/raw/93d4d7afaf0d59e142479052a785d63d8129d8b4/working-group-charter.pdf__;!0Ns9_1dOjwg!L_IHRWDKAjugqfAYNWdNwfIR4zRqmSXC6S-RacX8K66DGod-tTnqQ9Ml6_PayDE7D4vW0_Q$" target="_blank">
draft revised charter</a> say that the following is out of scope for the working group:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-left:0.5in">Definition of APIs and underlying mechanisms for connecting to, interacting with and operating centralized databases or intelligence clearinghouses when these are used to communicate security events between account
providers.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">So part of this discussion needs to be: is this work that we think belongs in the working group?<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal"><span style="font-size:12pt">– <u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt">Annabelle Richard Backman<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:12pt">AWS Identity<u></u><u></u></span></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:12pt;color:black">From: </span></b><span style="font-size:12pt;color:black">Openid-specs-risc <<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank">openid-specs-risc-bounces@lists.openid.net</a>> on behalf of Openid-specs-risc <<a href="mailto:openid-specs-risc@lists.openid.net" target="_blank">openid-specs-risc@lists.openid.net</a>><br>
<b>Reply-To: </b>David Skyberg <<a href="mailto:david.skyberg@capitalone.com" target="_blank">david.skyberg@capitalone.com</a>><br>
<b>Date: </b>Thursday, December 5, 2019 at 11:40 AM<br>
<b>To: </b>Openid-specs-risc <<a href="mailto:openid-specs-risc@lists.openid.net" target="_blank">openid-specs-risc@lists.openid.net</a>><br>
<b>Subject: </b>Re: [Openid-specs-risc] [External Sender] Re: reminder: call today at 3 pm Pacific<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Hi folks, <u></u><u></u></p>
<div>
<p class="MsoNormal">I would like to suggest a discussion topic - Clearing House support.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">The spec is currently targeted at point to point event exchange. There are also very valid use cases for supporting a pub/sub style clearing house model. This was the goal of Andrew Nash's startup, Confyrm (acquired by Capital One).<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">There are at least two interesting threads under this topic:<u></u><u></u></p>
</div>
<div>
<ul type="disc">
<li class="MsoNormal">
Event format, control plane, and protocol requirements for clearing house support. <u></u><u></u></li><li class="MsoNormal">
Privacy ('nuff said)<u></u><u></u></li></ul>
</div>
<div>
<p class="MsoNormal">I've had a couple very limited conversations (seriously, like 5 minutes) with Annabelle and Mike. Both agree we should at least start the discussion. I'm open to bribery. If you have a doc that needs editing, or your car needs cleaning,
I'm your guy.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><br clear="all">
<u></u><u></u></p>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal">Cheers,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">=D=<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><b><span style="font-family:Arial,sans-serif;color:rgb(44,82,128)">---</span></b><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><b><span style="font-family:Arial,sans-serif;color:rgb(44,82,128)">David Skyberg</span></b>
<u></u><u></u></p>
<div>
<p class="MsoNormal"><span style="font-family:Arial,sans-serif;color:rgb(44,82,128)">Product Director</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:Arial,sans-serif;color:rgb(44,82,128)">Capital One Identity Services</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:Arial,sans-serif;color:black">703.439.8876</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:Arial,sans-serif;color:black"><a href="mailto:david.skyberg@capitalone.com" target="_blank">david.skyberg@capitalone.com</a></span><u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Tue, Nov 26, 2019 at 6:27 PM Richard Backman, Annabelle via Openid-specs-risc <<a href="mailto:openid-specs-risc@lists.openid.net" target="_blank">openid-specs-risc@lists.openid.net</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal">Apologies for the confusion over the call today. We had some difficulties getting access to start the call. That should be resolved by the next one.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">We did hold a brief call this afternoon, which we ended early due to low participation (unsurprising, given the confusion). Notes from that meeting follow:<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal"><b>Re-Chartering Update</b><u></u><u></u></p>
<p class="MsoNormal">The proposed charter was submitted to the Specifications Council last week after amendment based on feedback received at the CAEP face-to-face meeting. We are awaiting confirmation
of the re-chartering from the Council.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal"><b>RISC Ramp Up</b><u></u><u></u></p>
<p class="MsoNormal">We answered a few questions regarding how to get ramped up on the RISC work, and how to participate:<u></u><u></u></p>
<ul type="disc">
<li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
<b>How can I learn about the work that the working group has done so far?</b> <u></u>
<u></u></li></ul>
<ul type="disc">
<ul type="circle">
<li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
Read the working group’s documents, available in <a href="https://urldefense.com/v3/__https:/bitbucket.org/openid/risc/src/master/__;!0Ns9_1dOjwg!JY0jeiE4y3ye6E_-a2dSiCZEgxpThPrsPV4nY70cbzPqHfMOwaGfEeRrVv7o5ntJNO33Ans$" target="_blank">
our repository</a> and on the OpenID Foundation <a href="https://urldefense.com/v3/__https:/openid.net/developers/specs/__;!0Ns9_1dOjwg!JY0jeiE4y3ye6E_-a2dSiCZEgxpThPrsPV4nY70cbzPqHfMOwaGfEeRrVv7o5ntJkFLwvbw$" target="_blank">
Specifications page</a>. There are three documents in total: <u></u><u></u></li></ul>
</ul>
<ul type="disc">
<ul type="circle">
<ul type="square">
<li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
<b>OpenID RISC Profile of IETF Security Events 1.0:</b> Describes our use of SET and SET transport mechanisms, and the Event Stream Management API.<u></u><u></u></li><li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
<b>OpenID RISC Event Types 1.</b>0: Defines event types for security events related to account-related use cases.<u></u><u></u></li><li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
<b>OAuth Event Types 1.</b>0: Defines event types for security events related to OAuth 2.0 use cases.<u></u><u></u></li></ul>
</ul>
</ul>
<ul type="disc">
<ul type="circle">
<li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
Read <a href="https://urldefense.com/v3/__http:/lists.openid.net/pipermail/openid-specs-risc/__;!0Ns9_1dOjwg!JY0jeiE4y3ye6E_-a2dSiCZEgxpThPrsPV4nY70cbzPqHfMOwaGfEeRrVv7o5ntJQnclMH4$" target="_blank">
the mailing list archive</a>, particularly meeting notes from past meetings. Unfortunately, these are not curated anywhere and the list does not have a good search mechanism.<u></u><u></u></li></ul>
</ul>
<ul type="disc">
<li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
<b>What is the best way to participate in the working group?</b> <u></u><u></u></li></ul>
<ul type="disc">
<ul type="circle">
<li class="gmail-m_-6971326574197881194gmail-m-5182224284296513160msolistparagraph">
The simplest and easiest way is to post to the mailing list (note that you must have an IPR agreement on file with the OpenID Foundation in order to participate).<u></u><u></u></li></ul>
</ul>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<p class="MsoNormal"><span style="font-size:12pt">– </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt">Annabelle Richard Backman</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt">AWS Identity</span><u></u><u></u></p>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:12pt;color:black">From:
</span></b><span style="font-size:12pt;color:black">"Richard Backman, Annabelle" <<a href="mailto:richanna@amazon.com" target="_blank">richanna@amazon.com</a>><br>
<b>Date: </b>Tuesday, November 26, 2019 at 3:03 PM<br>
<b>To: </b>Marius Scurtescu <<a href="mailto:marius.scurtescu@coinbase.com" target="_blank">marius.scurtescu@coinbase.com</a>>, Openid-specs-risc <<a href="mailto:openid-specs-risc@lists.openid.net" target="_blank">openid-specs-risc@lists.openid.net</a>><br>
<b>Subject: </b>Re: [Openid-specs-risc] reminder: call today at 3 pm Pacific</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<p class="MsoNormal">Scratch that, the call is open. We’ll see how many people make it, given the mixed messages.<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<p class="MsoNormal"><span style="font-size:12pt">– </span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt">Annabelle Richard Backman</span><u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:12pt">AWS Identity</span><u></u><u></u></p>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:12pt;color:black">From:
</span></b><span style="font-size:12pt;color:black">Openid-specs-risc <<a href="mailto:openid-specs-risc-bounces@lists.openid.net" target="_blank">openid-specs-risc-bounces@lists.openid.net</a>> on behalf of Openid-specs-risc <<a href="mailto:openid-specs-risc@lists.openid.net" target="_blank">openid-specs-risc@lists.openid.net</a>><br>
<b>Reply-To: </b>Marius Scurtescu <<a href="mailto:marius.scurtescu@coinbase.com" target="_blank">marius.scurtescu@coinbase.com</a>><br>
<b>Date: </b>Tuesday, November 26, 2019 at 2:49 PM<br>
<b>To: </b>Openid-specs-risc <<a href="mailto:openid-specs-risc@lists.openid.net" target="_blank">openid-specs-risc@lists.openid.net</a>><br>
<b>Subject: </b>Re: [Openid-specs-risc] reminder: call today at 3 pm Pacific</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">We are running into last minute technical issues and we won't be able to have the call today. Sorry about that.
<u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">We should be able to have the calls two weeks from today.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Best,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Marius<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<div>
<p class="MsoNormal">On Tue, Nov 26, 2019, 8:53 AM Marius Scurtescu <<a href="mailto:marius.scurtescu@coinbase.com" target="_blank">marius.scurtescu@coinbase.com</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin:5pt 0in 5pt 4.8pt">
<div>
<p class="MsoNormal">Just a reminder about the bi-weekly call today at 3 pm Pacific.
<u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">The embedded calendar and the iCal download are up to date, but the wording on the page still needs to be updated:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><a href="https://urldefense.com/v3/__https:/openid.net/wg/risc/__;!0Ns9_1dOjwg!JY0jeiE4y3ye6E_-a2dSiCZEgxpThPrsPV4nY70cbzPqHfMOwaGfEeRrVv7o5ntJLCYFT64$" target="_blank">https://openid.net/wg/risc/</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">In order to join the call:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Please join my meeting from your computer, tablet or smartphone.<br>
<br>
<a href="https://urldefense.com/v3/__https:/global.gotomeeting.com/join/576653581__;!0Ns9_1dOjwg!JY0jeiE4y3ye6E_-a2dSiCZEgxpThPrsPV4nY70cbzPqHfMOwaGfEeRrVv7o5ntJu1decNc$" target="_blank">https://global.gotomeeting.com/join/576653581</a><br>
You can also dial in using your phone.<br>
<br>
United States +1 (786) 358-5410<br>
<br>
Access Code: 576-653-581 <br>
<br>
More phone numbers<br>
Australia (Long distance): +61 2 9087 3604<br>
Austria (Long distance): +43 7 2088 1400<br>
Belgium (Long distance): +32 (0) 92 98 0592<br>
Canada (Long distance): +1 (647) 497-9350<br>
Denmark (Long distance): +45 69 91 88 62<br>
Finland (Long distance): +358 (0) 942 41 5778<br>
France (Long distance): +33 (0) 182 880 456<br>
Germany (Long distance): +49 (0) 692 5736 7211<br>
Ireland (Long distance): +353 (0) 14 845 976<br>
Italy (Long distance): +39 0 247 92 12 39<br>
Netherlands (Long distance): +31 (0) 208 080 379<br>
New Zealand (Long distance): +64 4 974 7215<br>
Norway (Long distance): +47 21 03 58 96<br>
Spain (Long distance): +34 911 82 9782<br>
Sweden (Long distance): +46 (0) 313 613 558<br>
Switzerland (Long distance): +41 (0) 225 3314 51<br>
United Kingdom (Long distance): +44 (0) 20 3535 0621<u></u><u></u></p>
</div>
</div>
</blockquote>
</div>
</div>
</div>
<p class="MsoNormal">_______________________________________________<br>
Openid-specs-risc mailing list<br>
<a href="mailto:Openid-specs-risc@lists.openid.net" target="_blank">Openid-specs-risc@lists.openid.net</a><br>
<a href="https://urldefense.com/v3/__http:/lists.openid.net/mailman/listinfo/openid-specs-risc__;!0Ns9_1dOjwg!JY0jeiE4y3ye6E_-a2dSiCZEgxpThPrsPV4nY70cbzPqHfMOwaGfEeRrVv7o5ntJoOLWS0s$" target="_blank">https://urldefense.com/v3/__http://lists.openid.net/mailman/listinfo/openid-specs-risc__;!0Ns9_1dOjwg!JY0jeiE4y3ye6E_-a2dSiCZEgxpThPrsPV4nY70cbzPqHfMOwaGfEeRrVv7o5ntJoOLWS0s$</a>
<u></u><u></u></p>
</blockquote>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="0" width="100%" align="center">
</div>
<p class="MsoNormal" style="margin-bottom:12pt"><br>
<br>
<span style="color:rgb(64,64,64)">The information contained in this e-mail is confidential and/or proprietary to Capital One and/or its affiliates and may only be used solely in performance of work or services for Capital One. The information transmitted herewith
is intended only for use by the individual or entity to which it is addressed. If the reader of this message is not the intended recipient, you are hereby notified that any review, retransmission, dissemination, distribution, copying or other use of, or taking
of any action in reliance upon this information is strictly prohibited. If you have received this communication in error, please contact the sender and delete the material from your computer.</span><u></u><u></u></p>
<table border="0" cellspacing="0" cellpadding="0" width="100%" style="width:100%">
<tbody>
<tr>
<td style="padding:0in"></td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><br>
<br>
<u></u><u></u></p>
</div>
</div>
</blockquote></div>
<HR><table border="0" cellspacing="0" cellpadding="0" width="100%" height="30"><BR>
<tr><BR>
<font color="#404040">The information contained in this e-mail is confidential and/or proprietary to Capital One and/or its affiliates and may only be used solely in performance of work or services for Capital One. The information transmitted herewith is intended only for use by the individual or entity to which it is addressed. If the reader of this message is not the intended recipient, you are hereby notified that any review, retransmission, dissemination, distribution, copying or other use of, or taking of any action in reliance upon this information is strictly prohibited. If you have received this communication in error, please contact the sender and delete the material from your computer.</font></td><BR>
</tr><BR>
</table><BR>