w3cping / privacy-threat-model

A target privacy threat model for the Web
https://w3cping.github.io/privacy-threat-model
Apache License 2.0
23 stars 7 forks source link

Sensitive-information: Add inferred restricted sensitive information #27

Open JoGSal opened 4 years ago

JoGSal commented 4 years ago

Not sure about the meaning of "the sensitivity of all kinds of information" but, unless redundant, could "inferring restricted sensitive information from cross-referencing not restricted sensitive information" be mentioned? Like the "minority inferred by language preferences" example in Sensitive information disclosure, a disability status could also be inferred by bits of information that are not restricted sensitive information on their own.

jyasskin commented 4 years ago

"There is not consensus about the sensitivity of all kinds of information", in context, means that, while there is consensus that some kinds of information are sensitive, and consensus that some kinds are not, there are also some kinds for which there isn't consensus.

Generally, if it's possible to confidently infer sensitive information from a set of other information, that makes the concurrent disclosure of all of that other information also sensitive. I think it does make sense for this document to say something about how confident that inference needs to be, but I'm not sure what it should say.

Could you send a pull request with the wording change you're thinking of?