8000 Update Security and privacy considerations by anssiko · Pull Request #47 · w3c/vibration · GitHub
[go: up one dir, main page]

Skip to content

Conversation

anssiko
Copy link
Member
@anssiko anssiko commented Oct 24, 2024

Expand "Request User Consent" considerations, add "Limit API Usage" considerations and suggested mitigations per W3C Security review feedback:

w3c/security-request#71


Preview | Diff

Expand "Request User Consent" considerations, add "Limit API Usage"
considerations and suggested mitigations per W3C Security
review feedback:

w3c/security-request#71
@anssiko anssiko requested a review from reillyeon October 24, 2024 08:41
index.html Outdated
Comment on lines 243 to 244
are encouraged to complement the normatively defined sticky
activation-based user activation-gating mitigation with the
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Encouraging implementers to implement normatively-defined things is weird. If they are normative then implementations should be doing them. This section probably needs a larger rewrite given that implementations currently do not inform the user when the API is in use either, or provide a mechanism to disable it.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, yes indeed. I think it is clearer to simply remove the sentence starting with "Implementers are encouraged to ...".

And, considering the intent of this specification update is to specify what is currently implemented, the appropriate RFC 2119 term to use in this context is MAY. If implementations agree to add these additional mitigations, we will adjust the term accordingly.

These fixes are at 1304787

@anssiko anssiko requested a review from reillyeon October 25, 2024 11:25
@himorin himorin added the security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response. label Oct 28, 2024
@anssiko anssiko merged commit d055733 into gh-pages Oct 28, 2024
1 check passed
@anssiko anssiko deleted the security-review-considerations branch October 28, 2024 11:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants
0