Re: deviceId and fingerprinting (or user tracking)

On 26/09/14 08:58, Martin Thomson wrote:
> On 25 September 2014 17:21, Shijun Sun <shijuns@microsoft.com> wrote:
>>
>> The deviceId is currently defined as an identifier which must be *persistent* between application sessions.  So a website can get the same deviceId's when a user visits the website using the same system, calling gUM() or not.  Should we expect the deviceId's for any specific website be (largely) consistent across all systems?  Otherwise, in the worst case when the Id is unique to each system, the website can potentially track the user.
>
> The requirement is that any deviceId information is cleared when
> cookies are cleared.  Thus, it doesn't offer any better tracking
> capability than is already available.

This is also my understanding. But, there is no text in the document 
that says that the info must be cleared when cookies are cleared, that 
is something we should add.


Received on Friday, 26 September 2014 07:09:47 UTC