-
Notifications
You must be signed in to change notification settings - Fork 386
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Privacy & Security explainer: Clarify threat vectors #748
Comments
Suggested additions to the XRPose section:
Suggested additions to the XRViewerPose section:
Suggested additions to the unbounded reference space:
Suggested additions to the bounded and local-floor sections:
|
I'm gonna try to get the PR landed as-is, but as soon as it is, please post a follow-up PR with these changes :) |
👍 SGTM! |
Feedback as requested! Mainly we just need to make sure we're describing the right objects/calls as having the protections applied to them. For example, the text quoted above isn't quite right because the consent requirements aren't actually for XRPose because |
@NellWaliczek I think that makes sense. I'd like to try again in an a PR, it'll be easier to match the logic in the context of the actual doc. SGTY? One approach that might work here is for that paragraph to be in the XRSession section, with XRPose largely removed...
|
Note: Per discussion, also add principles for when sensitive data is/is not considered a threat to the 2nd paragraph of the privacy & security explainer. An overview of principles from the above comment thread (IMO this needs to be edited for clarity and length):
|
After immersive-web#746 is merged, carry-forward work from this document into the privacy & security explainer is tracked at immersive-web#748, immersive-web#750, #753, immersive-web#754
Note to self: The language in the last bullet of this section suggests a particular timing for user consent, we can address this more precisely while elaborating on the IPD threat: https://github.com/immersive-web/webxr/blob/master/privacy-security-explainer.md#xrviewerpose |
Per feedback on #746 this issue is to track some additional text (in a new PR) to:
A few specific topics that probably should be covered...
XRPose section
Unbounded reference space
local-floor and bounded-floor
The text was updated successfully, but these errors were encountered: