w3c / wot-security

a repo exclusively for security to better manage issues and security considerations for WoT
https://w3c.github.io/wot-security/
18 stars 22 forks source link

Clarify that an Update System is Necessary for Security #135

Open mmccool opened 5 years ago

mmccool commented 5 years ago

In https://github.com/w3ctag/design-reviews/issues/355, it is mentioned that section on update in the Arch doc seems to imply that one should avoid updates https://w3c.github.io/wot-architecture/#sec-security-consideration-update-provisioning, however such updates are important to maintain security. A sentence should be added (before the mitigation) that updates are necessary to maintain the security of systems (the mitigation then states that updates need to be performed securely...).

mmccool commented 4 years ago

Related to lifecycle discussion, eg. "maintenance" state. When lifecycle is done in Architecture, we will need to rewrite the lifecycle section in S&PG document, and when THAT is done, we can close this issue.