Re: [compute-pressure] Feature can be abused to create cross-site covert channels (#197)

Hi @anssiko !

First, apologies for taking so long to reply. This looks terrific; sorry for not getting back to you quicker.

The only remaining feedback I have at this point is:
- some of the parameters in this process are implementation defined. It would be good to have some ceiling or floor for these, to ensure at minimum level of protection (otherwise, an implementation could have a complete and correct implementation the spec, without providing any protection) 
- it would be good to have some advisory text in the Security and privacy considerations section about what implementors should consider when selecting "implementation defined" values, and the tradeoffs in privacy vs other goals for different values.

But again, i think this is fantastic, and I'm impressed and grateful for the WG's terrific work here! This is a wonderful privacy improvement!

-- 
GitHub Notification of comment by pes10k
Please view or discuss this issue at https://github.com/w3c/compute-pressure/issues/197#issuecomment-1698413311 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 30 August 2023 02:55:57 UTC