Re: [mediacapture-main] Spec does no handle fingerprinting related to exposing non default capture devices (#559)

> I assume we're only talking about cross-site fingerprints, because:

Cross-site fingerprinting is one concern.
https://github.com/w3c/mediacapture-main/issues/563 is another issue, non default device labels have high value and can give insights to user preferences.
Exposing the timing of plug/unplug could potentially be used to learn about user habits (big data).

> I agree this fingerprint is unreliable for a (small) sub-population who might plug/unplug USB cameras occasionally, and that sites might use _enumerateDevices()_ to update this fingerprint for this sub-population from working some of the time, to all of the time. I also agree that, these configs being rare, their fingerprinting value is higher.
> 
> Do I have the value-add right?

Agreed.
As of unreliable for a small sub-population, maybe it will increase over time (BT headset, action cameras paired to laptop that could use them as regular camera/mic) but that increases other risks.

-- 
GitHub Notification of comment by youennf
Please view or discuss this issue at https://github.com/w3c/mediacapture-main/issues/559#issuecomment-457368397 using your GitHub account

Received on Thursday, 24 January 2019 21:44:12 UTC