Re: [w3c/permissions] Discuss how query() makes abuse harder to detect. (#166)

That text accurately describes the privacy threat, 👍 , but I'm not clear on what mitigations are being suggested (or any that have been implemented in the shipped features).

Ambient notices can be useful for things like location permission in general, but I'm not sure that provides easy detection of these piggybacking uses, especially since the case is a site where the user already explicitly granted a permission.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/permissions/pull/166#issuecomment-353681187

Received on Friday, 22 December 2017 21:59:54 UTC