w3cping / privacy-threat-model

A target privacy threat model for the Web
https://w3cping.github.io/privacy-threat-model
Apache License 2.0
23 stars 7 forks source link

Unwanted same-site recognition: should beacons be listed here too? #24

Closed JoGSal closed 4 years ago

JoGSal commented 4 years ago

Do beacons stop monitoring data (the behaviour of the user, the IP of the computer, the time and lenght the beacon was viewed, the type of browser, and previously set cookie values) after taking any of the actions listed under "A user might expect that their two visits won’t be associated if they:"?

jyasskin commented 4 years ago

https://www.w3.org/TR/beacon/ and https://fetch.spec.whatwg.org/#request-keepalive-flag don't describe any sort of monitoring, so I'm not sure if you're referring to something else or have misunderstood those features.

The kept-alive request should probably be ended when a site's storage is cleared, but that's an implication of the threat model, and not something that we need to specifically call out here.

JoGSal commented 4 years ago

Thank you, got that info from a definition search at https://www.webopedia.com/TERM/W/Web_beacon.html

The kept-alive request should probably be ended when a site's storage is cleared, but that's an implication of the threat model, and not something that we need to specifically call out here.

Clear