Re: [w3c/payment-handler] add a "public computing" section to security/privacy considerations (#244)

I still think the above is not in scope and distracts from more fundamental issues. For example, we haven’t even come to an agreement about what should happen when a user clears site data. 

Let’s focus on those more fundamental things first, as without solving those we won’t have an API at all. 

Regarding your questions above, I hold that they apply generally to all data held by browsers (e.g., passwords, form autofill, browsing history, etc). It’s not something we are going to solve in this spec. 

The TAG was going to define private browsing, iirc. So it might be something we give to them to document? 


-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/payment-handler/pull/244#issuecomment-357134524

Received on Friday, 12 January 2018 03:36:45 UTC