w3cping / privacy-threat-model

A target privacy threat model for the Web
https://w3cping.github.io/privacy-threat-model
Apache License 2.0
23 stars 7 forks source link

Attacker Capabilities: Read/Write storage #14

Open jumde opened 4 years ago

jumde commented 4 years ago

Access to storage in 1p/3p context is independent of javascript access. Storage is often used as a way track users across sites. Adding these capabilities would be helpful to highlight how to different privacy risks can be leveraged by attackers having/not-having access to storage across sites.