14:15:08 #startmeeting Acumos Security Subcommittee Meeting 14:15:08 Meeting started Tue Jul 31 14:15:08 2018 UTC. The chair is aimeeu. Information about MeetBot at http://wiki.debian.org/MeetBot. 14:15:08 Useful Commands: #action #agreed #help #info #idea #link #topic. 14:15:08 The meeting name has been set to 'acumos_security_subcommittee_meeting' 14:15:15 #chair bryan_att 14:15:15 Current chairs: aimeeu bryan_att 14:15:47 #topic Roll Call 14:18:52 #info Bryan Sullivan AT&T, Daniel Sela - Amdocs 14:19:36 #topic Release Planning 14:19:53 #info bryan added a roadmap page to the wiki 14:20:23 #info #link https://wiki.acumos.org/display/SEC/Release+Planning 14:22:04 #info Bryan adds items from Daniel 14:22:55 #info "automatic artifact reconstruction upon upload to the platform as necessary to ensure compiled model " matches the source" 14:23:11 #info Daniel: idea is NOT to let attacker take advantage 14:28:15 #info discussion on Python pickle and HD5 files 14:36:41 #info federation secured with client certificates 14:43:02 #info question on what can be done in Athena release 14:44:49 #topic Ongoing Items 14:45:03 #info still no response from LF on using NexusIQ 14:51:14 #topic security-verification component 15:00:23 #info Daniel: platform code contribution not a problem; if i want to download 8 models developed by TechM, i have to download, scan, review, approve - quite expensive; download and manually scanning does not solve the security/trust problem 15:00:38 #info Bryan: technical limitation for scanning: process-related inside Acumos (no mandate to upload source), metadata.json only lists dependencies needed to build microservice 15:00:58 #info Daniel asks if code is uploaded during onboarding 15:01:17 #info Bryan: for python, code technically is uploaded - trained models are uploaded as compressed data (pickle or HD5 - binary compressed representations of code - uncompressed is not full representation of source); no decompression tool for pickle files - you'd have to uncompress in python env which would potentially expose 15:01:50 #info Daniel would like to know exactly what happens when a model is on-boarded - what transformations take place and when 15:02:01 #info Bryan will talk to model on-boarding team 15:02:06 #endmeeting