[device-posture] Comparison to other fingerprinting surface is incorrect (#153)

pes10k has just created a new issue for https://github.com/w3c/device-posture:

== Comparison to other fingerprinting surface is incorrect ==
This issue is being filed as part of the PING review requested here https://github.com/w3cping/privacy-request/issues/136

Currently the security and privacy considerations section notes that there is some fingerprinting surface exposed here, which is correct (and appreciated). However, the exact comparison being made is incorrect or at least confusing. The given example is with # of touch points on the device. These are categorically different kinds of fingerprinting risk / surface though. # of touch points will be semi identifying but fixed (and so "typical" fingerprinting surface), while the time a "the device was just folded" signal was received will be very identifying but not fixed (and so "ephemeral fingerprinting").

Its great and appreciated to note the fingerprinting concern, but it would be ideal to correct the text here, and reference a similar ephemeral fingerprinting case (https://github.com/asankah/ephemeral-fingerprinting notes several)

Please view or discuss this issue at https://github.com/w3c/device-posture/issues/153 using your GitHub account


-- 
Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config

Received on Thursday, 18 July 2024 17:10:33 UTC