patcg-individual-drafts / topics

The Topics API
https://patcg-individual-drafts.github.io/topics/
Other
605 stars 199 forks source link

Specification is missing security considerations section #184

Open domenic opened 1 year ago

domenic commented 1 year ago

Although privacy is of course the more relevant question, security considerations should also be addressed in any specification, even if only to say there are none.

The main difference would be to think in terms of attackers and defenders, instead of colluding parties. E.g. is there a way a subframe could get info on the top-level site, using the topics API? Or vice versa? Things like that.