Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add "Security Considerations" and "Privacy Considerations" sections to the spec #261

Open
wolenetz opened this issue Nov 23, 2020 · 1 comment
Milestone

Comments

@wolenetz
Copy link
Member

As part of the evolving W3C TAG review process, new features involve a security and privacy questionnaire (https://www.w3.org/TR/security-privacy-questionnaire/) that it would be good to have in the V2 specification to assist
review of new features and, especially, to serve the intended purpose of helping implementers and web developers understand the risks that a feature presents, and to ensure that adequate mitigations are in place.

@wolenetz wolenetz added this to the V2 milestone Nov 23, 2020
@chrisn chrisn modified the milestones: V3, V2 Jul 21, 2023
@wolenetz
Copy link
Member Author

wolenetz commented Dec 4, 2023

One part to consider including relates to #175 : to not-overoptimize cross-thread communication, as such could enable (or reduce defenses against) timing attack vectors on susceptible platforms/implementations. See #175 (comment)

@chrisn chrisn mentioned this issue Aug 27, 2024
5 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants