w3c / gamepad

Gamepad
https://w3c.github.io/gamepad/
Other
141 stars 48 forks source link

Security / Privacy Questionnaire #76

Open jasonanovak opened 6 years ago

jasonanovak commented 6 years ago

PING was reviewing the May 8, 2018 Working Draft of the GamePad API and it doesn't include a Security & Privacy Considerations section.

Given the possible fingerprinting surface area exposed by the GamePad API and the mitigations within the API, it would be worthwhile for the spec to have a Security & Privacy Considerations section for the purposes of consolidating the privacy analysis in one place.

Additional considerations for drafting that section can be found here.

npdoty commented 6 years ago

The draft is already referring to mitigations for browser fingerprinting, but for more guidance on that topic (measuring severity and mitigations), this draft may be useful: https://w3c.github.io/fingerprinting-guidance/