W3C home > Mailing lists > Public > public-device-apis-log@w3.org > June 2017

Re: [ambient-light] Security and Privacy considerations for ALS

From: Anssi Kostiainen via GitHub <sysbot+gh@w3.org>
Date: Tue, 20 Jun 2017 07:26:58 +0000
To: public-device-apis-log@w3.org
Message-ID: <issue_comment.created-309668283-1497943617-sysbot+gh@w3.org>
My understanding is, the light-level media query as specified cannot be implemented in an interoperable manner, and as such, is not a solution to pursue at this time. Luckily, it seems that after careful research we've identified a solution that decreases entropy without compromising known high value use cases and allows us to mitigate known attacks.

I'll let @alexshalamov expand on the proposed solution with details, since that was hand-wavy on my part.

When we have these details discussed and agreed upon here, we are in a better position to update the security and privacy consideration section with concrete guidance to implementers -- and can finally close this issue that's been open for a while.

-- 
GitHub Notification of comment by anssiko
Please view or discuss this issue at https://github.com/w3c/ambient-light/issues/13#issuecomment-309668283 using your GitHub account
Received on Tuesday, 20 June 2017 07:27:04 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 12:18:53 UTC