finos / FDC3

An open standard for the financial desktop.
https://fdc3.finos.org
Other
187 stars 109 forks source link

FDC3 Identity & Threat Modelling - 9 Nov 2023 #1101

Closed Yannick-Malins closed 2 months ago

Yannick-Malins commented 7 months ago

Group overview

FDC3 revolves around several types of independent entities:

Each of these has an identity, and needs to know and trust the identities of several of the others in order to work seamlessly.However, at present there are few or no methods for them to validate those identities within the FDC3 Standard, meaning trust must be assumed. This comes with problems and risks : data loss, identity theft, oauth hell, or an inability to adopt interop via FDC3 - all of which are a threat to the FDC3 ecosystem’s continued growth. This complexity is multiplied by the different types of FDC3 setups now possible - desktop app interop, in-container interop, web interop, and interop between Desktop Agents (Bridging).

Over the past few years, various discussions, demos and roundtables have addressed this topic, but the outcome each time has been “what do our users need?”.

Therefore our first objective in this stream is to dig into what these risks and problems are, before we discuss and work on potential solutions

Relevant issue tags

https://github.com/finos/FDC3/labels/identity-security

Meeting Date

Thursday 9 Nov 2023 - 11am (US eastern timezone EDT/EST) / 4pm (London, GMT/BST)

Zoom info

Meeting notices

Agenda

Minutes

Action Items

Untracked attendees

Full name Affiliation GitHub username
Yannick-Malins commented 7 months ago

After a first session focused mainly on application and agent identity, this second session will focus on user identity

bingenito commented 7 months ago

Brian Ingenito / Morgan Stanley

mattjamieson commented 7 months ago

Matt Jamieson / WhiteDog

kriswest commented 7 months ago

Kris West / Interop.io 🚀

robmoffat commented 7 months ago

Rob / FINOS 🐟

hughtroeger commented 7 months ago

Hugh Troeger / FactSet

paulgoldsmith commented 7 months ago

Paul Goldsmith / Morgan Stanley

kriswest commented 4 months ago

Need minutes before closing - perhaps worth trying an AI summarize on recording/transcript?

bingenito commented 4 months ago

@kriswest This might have to be an update to agreements and reviewed by participants Legal teams. There is currently an assumption that the recordings are private and only for internal use, sending that to a service for summary might require notification and sign-off from all participants.