w3c / wot-security

a repo exclusively for security to better manage issues and security considerations for WoT
https://w3c.github.io/wot-security/
18 stars 22 forks source link

Security implications of import #106

Closed mmccool closed 6 years ago

mmccool commented 6 years ago

We should discuss the security implications of the import mechanism proposed here: https://github.com/w3c/wot-thing-description/issues/168

More generally, "links" may also need security mechanisms, or have security implications. How can we know whether we can trust the entity at the other end of a link, or know if the entity responding to the link is the right entity?

mmccool commented 6 years ago

Looks like this will be a non-issue since it doesn't look like there will be consensus to add this feature to TDs.

mmccool commented 6 years ago

Non-issue (out of scope), will not be in the standard.