w3c / vibration

Vibration API
https://w3c.github.io/vibration/
Other
13 stars 11 forks source link

Structuring the security considerations section #49

Open simoneonofri opened 1 week ago

simoneonofri commented 1 week ago

This issue refers to the security review requested in this issue https://github.com/w3c/security-request/issues/71

Structuring the Security Considerations section along the lines of RFC 3552 and as discussed in https://github.com/w3c/security-request/issues/71#issuecomment-2440005127.

If there are any doubts, we remain available.

Thank you

[cc'ing @anssiko, @himorin, @KimCerra]

anssiko commented 1 week ago

Thank you @simoneonofri. I'd also note the group's prior work in this space: the Generic Sensor API and Compute Pressure API threats and mitigations. To be updated based on learnings from this restructuring exercise.

anssiko commented 2 days ago

Status update: the group's imminent plan is to publish a new CRS and incorporate restructured security considerations in a subsequent specification update. The group is committed to work closely with @simoneonofri and other security experts to help dogfood emerging guidelines for writing security considerations for W3C specs (a la RFC 3552) as outlined in this issue.