Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add initial content to Security and Privacy Considerations sections. #189

Merged
merged 3 commits into from
Dec 5, 2024

Conversation

msporny
Copy link
Contributor

@msporny msporny commented Nov 14, 2024

Based on the 2024-11-13 WICG Digital Credentials telecon, this PR adds some basic content to the security considerations and privacy considerations sections noting that the group has done some thinking in this area and plans to continue and expand upon that work during the Working Group.

/cc @npdoty @timcappalli @samuelgoto @RByers @marcoscaceres

PS: I don't have any strong opinions on any of the content, just trying to be responsive to @npdoty's request and produce something for the group to discuss and merge.


💥 Error: 500 Internal Server Error 💥

PR Preview failed to build. (Last tried on Dec 3, 2024, 1:41 PM UTC).

More

PR Preview relies on a number of web services to run. There seems to be an issue with the following one:

🚨 Spec Generator - Spec Generator is the web service used to build specs that rely on ReSpec.

🔗 Related URL

Timed out after waiting 30000ms

If you don't have enough information above to solve the error by yourself (or to understand to which web service the error is related to, if any), please file an issue.

"https://github.com/WICG/digital-credentials/blob/main/horizontal-reviews/security-privacy.md">
TAG Security and Privacy Considerations Questionnaire (WIP)</a>
</li>
</ul>

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would propose to add also the Threat Model, as defined in the (re)charter

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in 2645588.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@msporny thank you

Copy link
Member

@RByers RByers left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for my delay, this looks like a great fist cut at a framework to me. I say we land it (with or without the suggestion of linking to the threat model) and then focus on getting in the habit of making regular incremental improvements.

"https://github.com/WICG/digital-credentials/blob/main/horizontal-reviews/security-privacy.md">
TAG Security and Privacy Considerations Questionnaire (WIP)</a>
</li>
</ul>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed

Digital Credentials, both broadly and for presentation on the web.
Their contents will be integrated into this document gradually.
</p>
<ul>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add the threat model here too? It's probably even more about privacy than security I'd say right @simoneonofri?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@RByers, the generic one is a hybrid of security and privacy as per the frameworks used so that it can fit one or both

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in 2645588.

@RByers
Copy link
Member

RByers commented Dec 2, 2024

Let's give it 24 hours to see if anyone else wants to add comments, and then if there are no objections I'll merge it.

index.html Show resolved Hide resolved
index.html Show resolved Hide resolved
@simoneonofri simoneonofri self-requested a review December 3, 2024 14:20
"https://github.com/WICG/digital-credentials/blob/main/horizontal-reviews/security-privacy.md">
TAG Security and Privacy Considerations Questionnaire (WIP)</a>
</li>
</ul>

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@msporny thank you

@npdoty
Copy link

npdoty commented Dec 3, 2024

Definitely an improvement to at least have an outline of some of the concerns, both for the spec or for what other ecosystem pieces are involved.

I'll mention this topic on the Privacy WG call this week and see if I or others have the time to also add in some initial content to these sections.

Copy link
Member

@timcappalli timcappalli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@RByers RByers merged commit 2d6ce1d into WICG:main Dec 5, 2024
1 check passed
@RByers
Copy link
Member

RByers commented Dec 5, 2024

Thank you all, merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants