finos / FDC3

An open standard for the financial desktop.
https://fdc3.finos.org
Other
187 stars 109 forks source link

FDC3 Identity & Threat Modelling -14 Mar 2024 #1172

Closed Yannick-Malins closed 3 months ago

Yannick-Malins commented 3 months ago

Group overview

FDC3 revolves around several types of independent entities:

Each of these has an identity, and needs to know and trust the identities of several of the others in order to work seamlessly.However, at present there are few or no methods for them to validate those identities within the FDC3 Standard, meaning trust must be assumed. This comes with problems and risks : data loss, identity theft, oauth hell, or an inability to adopt interop via FDC3 - all of which are a threat to the FDC3 ecosystem’s continued growth. This complexity is multiplied by the different types of FDC3 setups now possible - desktop app interop, in-container interop, web interop, and interop between Desktop Agents (Bridging).

Over the past few years, various discussions, demos and roundtables have addressed this topic, but the outcome each time has been “what do our users need?”.

Therefore our first objective in this stream is to dig into what these risks and problems are, before we discuss and work on potential solutions

Relevant issue tags

https://github.com/finos/FDC3/labels/identity-security

Meeting Date

Thursday 14 Mar 2024 - 3pm GMT

Zoom info

Meeting notices

Agenda (60mn)

Minutes

The entire discussion revolved around building and refining a set of "core use-cases" that can be used to analyse the different potential solutions (signing, symmetric or asymmetric encrypting etc).

Action Items

Yannick & Rob to propose solutions and build the solution/use-case matrix

kriswest commented 3 months ago

Kris West / interop.io 🚀

robmoffat commented 3 months ago

Rob / FINOS ⛳

mistryvinay commented 3 months ago

Vinay Mistry / Symphony 🎵

openfin-johans commented 3 months ago

Johan Sandersson / OpenFin 🎁

paulgoldsmith commented 3 months ago

Paul Goldsmith / Morgan Stanley

Lecss commented 3 months ago

Alex Dumitru / Citi

hughtroeger commented 3 months ago

Hugh Troeger / FactSet

Yannick-Malins commented 3 months ago

Yannick Malins / Symphony