finos / FDC3

An open standard for the financial desktop.
https://fdc3.finos.org
Other
193 stars 115 forks source link

FDC3 Identity & Threat Modelling -11 July 2024 #1257

Closed Yannick-Malins closed 3 weeks ago

Yannick-Malins commented 1 month ago

Group overview

FDC3 revolves around several types of independent entities:

Each of these has an identity, and needs to know and trust the identities of several of the others in order to work seamlessly.However, at present there are few or no methods for them to validate those identities within the FDC3 Standard, meaning trust must be assumed. This comes with problems and risks : data loss, identity theft, oauth hell, or an inability to adopt interop via FDC3 - all of which are a threat to the FDC3 ecosystem’s continued growth. This complexity is multiplied by the different types of FDC3 setups now possible - desktop app interop, in-container interop, web interop, and interop between Desktop Agents (Bridging).

Over the past few years, various discussions, demos and roundtables have addressed this topic, but the outcome each time has been “what do our users need?”.

Therefore our first objective in this stream is to dig into what these risks and problems are, before we discuss and work on potential solutions

Relevant issue tags

https://github.com/finos/FDC3/labels/identity-security

Meeting Date

Thursday 11 July 2024 - 2pm GMT

Zoom info

Meeting notices

Agenda (50mn)

Minutes

Re-presented the flow diagrams from https://github.com/finos/FDC3/issues/1227

Participants agreed that the e2e encrypted channel flow solves all the business usecases previously listed

Analysing potential impact on desktop agents:

Next objective: Get two firms to build and demonstrate a proof of concept implementation (OSFF NYC?), before standardisation

kriswest commented 1 month ago

Kris West / interop.io 🚀

paulgoldsmith commented 1 month ago

Paul Goldsmith / Morgan Stanley

robmoffat commented 1 month ago

Rob. Moffat / FINOS 🧇

Yannick-Malins commented 1 month ago

Yannick Malins / Symphony