-
Notifications
You must be signed in to change notification settings - Fork 12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add initial content to Security and Privacy Considerations sections. #189
Conversation
"https://github.com/WICG/digital-credentials/blob/main/horizontal-reviews/security-privacy.md"> | ||
TAG Security and Privacy Considerations Questionnaire (WIP)</a> | ||
</li> | ||
</ul> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I would propose to add also the Threat Model, as defined in the (re)charter
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Agreed
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done in 2645588.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@msporny thank you
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sorry for my delay, this looks like a great fist cut at a framework to me. I say we land it (with or without the suggestion of linking to the threat model) and then focus on getting in the habit of making regular incremental improvements.
"https://github.com/WICG/digital-credentials/blob/main/horizontal-reviews/security-privacy.md"> | ||
TAG Security and Privacy Considerations Questionnaire (WIP)</a> | ||
</li> | ||
</ul> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Agreed
Digital Credentials, both broadly and for presentation on the web. | ||
Their contents will be integrated into this document gradually. | ||
</p> | ||
<ul> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Add the threat model here too? It's probably even more about privacy than security I'd say right @simoneonofri?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@RByers, the generic one is a hybrid of security and privacy as per the frameworks used so that it can fit one or both
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done in 2645588.
Let's give it 24 hours to see if anyone else wants to add comments, and then if there are no objections I'll merge it. |
"https://github.com/WICG/digital-credentials/blob/main/horizontal-reviews/security-privacy.md"> | ||
TAG Security and Privacy Considerations Questionnaire (WIP)</a> | ||
</li> | ||
</ul> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@msporny thank you
Definitely an improvement to at least have an outline of some of the concerns, both for the spec or for what other ecosystem pieces are involved. I'll mention this topic on the Privacy WG call this week and see if I or others have the time to also add in some initial content to these sections. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Thank you all, merged. |
Based on the 2024-11-13 WICG Digital Credentials telecon, this PR adds some basic content to the security considerations and privacy considerations sections noting that the group has done some thinking in this area and plans to continue and expand upon that work during the Working Group.
/cc @npdoty @timcappalli @samuelgoto @RByers @marcoscaceres
PS: I don't have any strong opinions on any of the content, just trying to be responsive to @npdoty's request and produce something for the group to discuss and merge.
💥 Error: 500 Internal Server Error 💥
PR Preview failed to build. (Last tried on Dec 3, 2024, 1:41 PM UTC).
More
PR Preview relies on a number of web services to run. There seems to be an issue with the following one:
🚨 Spec Generator - Spec Generator is the web service used to build specs that rely on ReSpec.
🔗 Related URL
If you don't have enough information above to solve the error by yourself (or to understand to which web service the error is related to, if any), please file an issue.