w3cping / privacy-threat-model

A target privacy threat model for the Web
https://w3cping.github.io/privacy-threat-model
Apache License 2.0
23 stars 7 forks source link

Describe navigation as a capability, not a goal. #33

Open jyasskin opened 4 years ago

jyasskin commented 4 years ago

This reduces the number of goal columns at the cost of increasing the number and complexity of rows in the table. I hope it makes it easier to see what abilities an attacker gains when they're willing to show the user a navigation.

This depends on #32 to make sure the resulting columns all match up.


Preview | Diff

jyasskin commented 4 years ago

Yep, this change is the third in a stack that all collide with eachother. You can review just one using a dropdown in the "Files changed" pane:

"Changes from 1 commit" dropdown