w3c-ccg / did-method-web

DRAFT: did:web Decentralized Identifier Method Specification
https://w3c-ccg.github.io/did-method-web/
Other
32 stars 17 forks source link

Add language about correlation risk to individuals #9

Closed msporny closed 2 years ago

dmitrizagidulin commented 3 years ago

@msporny +1 to this PR overall (we've been meaning to add this section for a while).

We should get more specific with the warnings, though.

For example, verification of a Verifiable Presentation might result in resolving a did:web DID by the verifier. This enables the DID Method registry Verifiable Data Registry to know when and where every did:web DID on the ledger is used, which is useful when tracking behaviour of the DID subject.

The "when and where every did:web DID ... is used" is not quite right. We should say something more like:

"For example, the verification of a Verifiable Presentation might result in a verifier resolving a did:web DID. As with any HTTP request, this resolution enables the Verifiable Data Registry (the server where the DID is hosted) to track a number of things, both about the verifier and the DID itself. (Incidentally, these concerns apply to any DID methods accessed through an http-based Universal Resolver of any sort hosted on a public website.)

DID:

Verifier:

OR13 commented 3 years ago

unclear what changes need to be accepted to see this merged.

dmitrizagidulin commented 3 years ago

@OR13 - I'd like the warnings to be more specific. (discussing this with @msporny)

OR13 commented 3 years ago

PR is stale and should be closed.

msporny commented 3 years ago

Yes, it's stale. If we close this, the text should be preserved and integrated into the new spec.

OR13 commented 3 years ago

https://github.com/w3c-ccg/did-method-web/issues/29

This PR should be closed if the requested changes cannot be implemented in a timely manner.

@dmitrizagidulin @awoie I recommend adding a "pending-close" / 1 week tag.

OR13 commented 3 years ago

@msporny this PR has conflicts and changes requested, if they are not addressed in 1 week it will be closed, if you wish for these concerns to be addressed, please open issues to track them.

OR13 commented 2 years ago

Closing the PR, feel free to open another one at any time.