Re: [web-nfc] Security review

I am not sure how much of an issue that actually is. Generally loading web sites is not dangerous due to the sandbox of the web, but you can of course encode specific URLs like ?location=showonsecondstreet and that way somehow track where the user is, but it might not really be a big issue.

Actually as Android can already launch the browser for URLs then it makes little sense for this spec to conflict with it and try to do the same. On the other hand it would be nicer to actually launch the site and then somehow still be able to get the info read from the NFC from the site, a bit like Web Bluetooth discussed having the navigator.bluetooth.referringDevice when launched from a bluetooth beacon.

-- 
GitHub Notification of comment by kenchris
Please view or discuss this issue at https://github.com/w3c/web-nfc/issues/22#issuecomment-351344781 using your GitHub account

Received on Wednesday, 13 December 2017 10:09:39 UTC