igrigorik / http-client-hints

402 stars 24 forks source link

Add Privacy Considerations section #49

Closed igrigorik closed 9 years ago

igrigorik commented 9 years ago

From @sleevi on blink-dev:

It doesn't seem like there's anything substantive in the spec about the privacy implications, other than two sentences under Security Considerations. It seems at least worth calling out explicitly, even though https://www.chromium.org/Home/chromium-security/client-identification-mechanisms and http://www.w3.org/wiki/Fingerprinting exist. For example, https://w3ctag.github.io/security-questionnaire/ has a good set of questions that should ideally be documented in the spec