w3ctag / design-reviews

W3C specs and API reviews
Creative Commons Zero v1.0 Universal
328 stars 55 forks source link

Local Peer-to-Peer API #932

Open anssiko opened 7 months ago

anssiko commented 7 months ago

こんにちは TAG-さん!

I'm requesting a TAG review of the Local Peer-to-Peer API.

Further details:

You should also know that...

The following design considerations would especially welcome TAG's feedback:

Implementation experiments

To help inform the API design, we are conducting a series of experiments to evaluate the feasibility of the design:

We'd prefer the TAG provide feedback as (please delete all but the desired option):

🐛 open issues in our GitHub repo for each point of feedback

torgo commented 5 months ago

Hi @anssiko we are looking at this and we think it may be good to do a special session on it where you could join and present? This feels like a real major new feature. We're thinking one of our regular breakouts in the first week of May?

simoneonofri commented 5 months ago

Hello @anssiko, @ibelem, @backkem, and @wangw-1991,

The work looks very interesting to me, congratulations.

Regarding security and privacy, could you include a specific threat model for this issue? In addition to the typical cases already in the Open Screen Protocol (e.g., Passive Network Attackers, Active Network Attackers, DoS), it would be interesting to consider possible Abuse of Functionalities (so what a threat actor can implement with this technology) and reason about mitigations. To give some examples:

anssiko commented 5 months ago

@torgo @simoneonofri thanks for the initial feedback. We're happy to join your breakout with @backkem. Let us know when you have a date and time and we sync calendars.

@ibelem and @wangw-1991 are UTC+8 so it might be hard to find a slot that works for all -- I'll volunteer to bring their perspective and contributions into this breakout.

matatk commented 4 months ago

Sorry for the delay in getting back to you. We'd like to invite you to join one of our breakout calls for the week of the 10th of June:

/cc @martinthomson

backkem commented 4 months ago

Breakout E would fit me best but I can make all of them.

anssiko commented 4 months ago

Breakout E works for me too.

wangw-1991 commented 4 months ago

Breakout E works for me too.

simoneonofri commented 4 months ago

Breakout E works for me

matatk commented 4 months ago

Great, thanks @backkem, @anssiko, @wangw-1991, @simoneonofri. We will go with Breakout E (07:00 UTC, 12 June 2024) - we're looking forward to the discussion.

I'll figure out how to get you a calendar invite (I think we must have at least most of your contact details already; I'll confer with the rest of the group).

anssiko commented 4 months ago

@matatk please let us know if you need help setting up the invite. If you're missing some contact information you can ping me offline too.

matatk commented 3 months ago

@backkem, @anssiko, @wangw-1991, @simoneonofri: I sent out an invite last week, and I have replies from almost (if not) all of you for tomorrow's call (I got your email addresses from the 'W3C Groups' site).

If you didn't get the invite, or need any clarification, please let me know. If you need to reach me via email, you can find my address via the 'W3C Groups' site.

We are looking forward to learning more about this API tomorrow.

matatk commented 3 months ago

Hi all, and thank you again for the recent discussion. Our minutes, including minutes from our call, have been published - please let us know if you spot anything wrong, or missing. Our suggestions for further clarification/possible next steps in a number of areas, as we discussed, are noted there.

We also had a discussion in our plenary session the same week. We wanted to highlight one area where we have concerns: the security of the handshaking process (this came up in the call, but as it was also discussed in the plenary session, we wanted to point you to it).

Feel free to ping us via this thread as and when you have updates; thanks.

autonome commented 3 months ago

Hi @matatk! The plenary discussion link points to the call minutes link.

matatk commented 3 months ago

Hi @autonome, are you using the GitHub mobile app by any chance? It doesn't seem to jump to the correct parts of the document (both discussions are in one document) - if you are able to follow the links in a browser, you should be taken to the correct parts of the minutes.

autonome commented 3 months ago

User error: I see now that they are two separate parts of the same notes document, sorry!

torgo commented 2 months ago

Hi @anssiko just wondering if there has been any update after our discussion. Thanks!

anssiko commented 3 weeks ago

@torgo thanks for the ping. We'll have a discussion at TPAC at around 11 am on Friday 27 Sep https://github.com/w3c/secondscreen-wg/issues/11 You're welcome to join us.

I will be there and I believe @martinthomson should be also there in person representing the TAG. @backkem will join remotely. We can use that session to discuss our path forward and continue translate valuable TAG breakout feedback into concrete issues.