w3c-fedid / FedCM

A privacy preserving identity exchange Web API
https://w3c-fedid.github.io/FedCM/
Other
369 stars 72 forks source link

Privacy of Directed Identifiers and Competitive consequences of centralized IDPs #42

Open dialtone opened 3 years ago

dialtone commented 3 years ago

I may have missed discussion on these 2 topics in other issues or in the spec itself but it's not clear to me how this specification would protect from the following:

cheers!

timcappalli commented 3 years ago

Suggested solution – some mechanism for directed identities having an IdP-less recovery mechanism baked in. This may be taken as a poison pill, since it raises the bar for use of their directed identities all up, but from a long-term support standpoint, it seems important.