w3c / websub

WebSub Spec in Social Web Working Group
https://w3c.github.io/websub/
285 stars 50 forks source link

How to ensure publisher and subscriber data remains private when transmitted through hubs? #173

Open markcellus opened 2 years ago

markcellus commented 2 years ago

First, I'd like to say that I am in love this specification! :heart:

I've been reading it, but I'm having difficulty understanding something.

While Hubs are meant to transmit activity and serve as an intermediary between subscribers and publishers, this would give Hubs an opportunity to store the (meta)data that is being transmitted between subscribers and publishers.

I may have missed it (I've taken a look at the Security and Privacy section of the spec), but how will the specification address Hubs that may store information (on their own proprietary servers) as it's being transmitted between subscribers and publishers?