Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Split security & privacy considerations #224

Closed
samuelweiler opened this issue Nov 15, 2021 · 2 comments
Closed

Split security & privacy considerations #224

samuelweiler opened this issue Nov 15, 2021 · 2 comments
Labels
editorial privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response.

Comments

@samuelweiler
Copy link
Member

Please split security and privacy considerations into separate sections, as it has been claimed was done here, but appears to have not yet been done. w3c/security-request#17 (comment)

@samuelweiler samuelweiler added privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response. labels Nov 15, 2021
@samuelweiler
Copy link
Member Author

We have changed the guidance, and while separate security and privacy sections are still recommended, they are not required. Feel free to close this issue or not, as you prefer.

@marcoscaceres
Copy link
Member

Hi @samuelweiler, as a followup, we've integrated the security requirements more directly into normative sections of the spec. The Privacy section now describes the privacy mitigations are in place throughout the spec.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
editorial privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. security-tracker Group bringing to attention of security, or tracked by the security Group but not needing response.
Projects
None yet
Development

No branches or pull requests

2 participants