Re: [w3c/screen-orientation] Add Privacy and Security Considerations section (#115)

chaals requested changes on this pull request.

This answers the questions posed by the security/privacy questionnaire, but doesn't give much useful information.

I think the point is to explain what someone might do with that information that has an impact on security and privacy.

Although it is potentially possible to lock the orientation of a device, about the only application I can think of where there is an issue is something like a compass, where it is possible to actively mislead the user. In practice, that is already possible with a compass application.

Kowing whether the user is turning their device is indeed a potential fingerprinting vector (like so many things related to sensors, also because it can be corroborated externally, e.g. by processing surveillance video of an area). However, it is a relatively complex and inefficient attack to use - in practice I would not expect to see it deployed unless users become far-more privacy concsious and protect themselves against many simpler attacks.



-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/screen-orientation/pull/115#pullrequestreview-123803927

Received on Monday, 28 May 2018 20:05:30 UTC