[css-houdini-drafts] [css-paint-api] CSS Paint API leaks browsing history

deian has just created a new issue for https://github.com/w3c/css-houdini-drafts:

== [css-paint-api] CSS Paint API leaks browsing history ==
The [Privacy considerations](https://www.w3.org/TR/2018/CR-css-paint-api-1-20180809/#privacy-considerations) should be updated in my option to reflect the dangers of leaking browser history (at high rates). We have a paper that will be published next week at WOOT discussing this ([my copy here](https://cseweb.ucsd.edu/~dstefan/pubs/smith:2018:browser.pdf)). Chromium addressed this by disabling the API on link elements and their children.

Please view or discuss this issue at https://github.com/w3c/css-houdini-drafts/issues/791 using your GitHub account

Received on Friday, 10 August 2018 19:51:30 UTC