w3c-fedid / FedCM

A privacy preserving identity exchange Web API
https://w3c-fedid.github.io/FedCM/
Other
375 stars 72 forks source link

Nonce is a sensitive word in the UK #461

Closed npm1 closed 1 year ago

npm1 commented 1 year ago

Per wikipedia: "Nonce, a slang term chiefly used in Britain for alleged or convicted sex offenders, especially ones involving children."

We are using the term in the FedCM spec, obviously not with that meaning. This issue is to consider changing to term to "challenge", like WebAuthn uses, or to decide that it is too late to do so.

domfarolino commented 1 year ago

There's generally a lot of precedent for this term on the web platform. See https://html.spec.whatwg.org/C#nonce-attributes for example. That might not be a great reason to keep using it, but my 2c as a non-editor of this spec would be to just keep using it, in part because it is not really condemning a marginalized group of people, and because changing it sounds like a low-priority pain. We could optionally file something on the TAG design principles to ask for further consideration more broadly and set a precedent in their spec if there is appetite to....not sure...

npm1 commented 1 year ago

That is fair. While I filed this bug, it was someone else who noted this. That said, given the precedent of other nonces in the web, I think it is fair to close this.