w3cping / privacy-threat-model

A target privacy threat model for the Web
https://w3cping.github.io/privacy-threat-model
Apache License 2.0
23 stars 7 forks source link

Describe assistive tech as sensitive, not benign. #22

Closed jyasskin closed 3 years ago

jyasskin commented 4 years ago

And avoid describing the user's choice of connected hardware as benign.

As, I believe, @joshueoconnor pointed out in https://lists.w3.org/Archives/Public/public-privacy/2020JanMar/0012.html, whether a user uses assistive technology is sensitive, not benign. This drove the design of AOM's new input events in non-obvious ways, so it deserves to be called out here.


Preview | Diff

joshueoconnor commented 4 years ago

Thanks for bringing this up @jyasskin

jyasskin commented 3 years ago

Thanks for the Design Principles link; I've added that.

I think it's unclear whether the presence of a game controller is sensitive. It could certainly help target ads, and the type of game controller could reveal things like social class. Other attached hardware seems similar. Rather than try to figure all that out in this PR, it seemed easier to drop the item I had questions about, and just fix the obvious mistake.