Re: [w3c/manifest] Add id member to manifest (#988)

Difficult case also, for an attacker, is knowing IF they should search or not. Impossible to know the the visit is a new user or not. Second, if they are serving a new manifest all of the time trying to figure out this id, the id will always be different, allowing any of these 'searching' apps to be installed. This makes the search now inconclusive, as any of those new ids would trigger false positives with the search, and cause the id association to be wrong.

Regarding other fields that are sensitive here - I don't think any of them affect future behavior? I don't see how they would cause privacy exposure.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/manifest/pull/988#issuecomment-902203041

Received on Thursday, 19 August 2021 20:02:08 UTC