Re: [compute-pressure] Feature can be abused to create cross-site covert channels (#197)

@pes10k thank you for your continued feedback and advice that allow us to go beyond the usual expectations in this space! The WG is [explicitly chartered](https://www.w3.org/2022/11/das-wg-charter.html#scope) to develop secure and privacy-preserving specifications and we're truly committed to that. Obviously this wouldn't be possible without collaboration with and contributions from privacy experts across W3C groups and academia.

I'm happy to see we're now on the PING TPAC meeting agenda (Tue 12 Sep, 17:00-18:30 Seville local). I think the approach to implementation-defined keyword, normative baseline floor and ceiling, might be good discussion topics with the broader PING audience. I'll pencil that in as one specific discussion point for this meeting.

As you know, the Infra Standard [implementation-defined](https://infra.spec.whatwg.org/#implementation-defined) keyword is used in many specs. Perhaps Infra should give more elaborate advice to spec authors on how to use this keyword in the most appropriate way? Maybe we can propose something that'd generalize to other specs too. Let's discuss at the meeting.

-- 
GitHub Notification of comment by anssiko
Please view or discuss this issue at https://github.com/w3c/compute-pressure/issues/197#issuecomment-1698631273 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Wednesday, 30 August 2023 07:21:10 UTC