w3c / tvcontrol-api

TV Control API specification - https://w3c.github.io/tvcontrol-api/
10 stars 11 forks source link

Privacy issues and API design #26

Open stevem-tw opened 7 years ago

stevem-tw commented 7 years ago

The TV Control API has the potential to expose a lot of information to a web app that can be used to track the user's behaviour through a variety of ways. For example:

This ties in with the discussion about application types and which capabilities should be provided to applications. We will need to be careful to ensure that the information we expose doesn't offer unforseen ways of violating the privacy of the user through hostile applications.

chrisn commented 7 years ago

I definitely agree. I previously wrote some notes in this issue, following the W3C's security and privacy guidance questionnaire.