Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make mandatory link between image metadata and page permissions #283

Open
pes10k opened this issue Jul 16, 2021 · 3 comments
Open

Make mandatory link between image metadata and page permissions #283

pes10k opened this issue Jul 16, 2021 · 3 comments
Labels
privacy-needs-resolution Issue the Privacy Group has raised and looks for a response on.

Comments

@pes10k
Copy link

pes10k commented Jul 16, 2021

(this issue is from the review I did as part of PING's HR review)

Currently, the spec mentions, non-normatively, that implementors might consider preventing unexpected information loss through image headers. The risks for privacy loss here is significant, and could even weaken privacy protections enforced elsewhere in the platform (as an example, geolocation information might be leaked to the page through an EXIF header in an image, despite the page not having the geolocation permission).

The spec should, normatively, ensure that the new functionality in the spec doesn't cause such privacy harm.

Two possible suggestions for how the spec could do this:

  1. Simplest idea: specify that there MUST NOT be any metadata attached to the returned image
  2. More difficult idea: specify what kinds of data MAY be attached to the image, and consider that a closed set

The above are just offered as suggestions, but the core of the issue here is that the spec should deal with this introduced privacy risk through normative / required protections.

@EricMwobobia
Copy link

@pes10k any update on the issue? From the fingerprinting issues raised in the media capture stream, I believe stripping excessive metadata is a good privacy approach. We can also review the various data to trim the excessive data to be used in fingerprinting if need be.

@pes10k
Copy link
Author

pes10k commented Aug 19, 2021

@EricMwobobia i have not heard anything back from the WG in response to PINGs review

@beaufortfrancois
Copy link
Contributor

@riju Can you have a look?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
privacy-needs-resolution Issue the Privacy Group has raised and looks for a response on.
Projects
None yet
Development

No branches or pull requests

3 participants