Re: [w3ctag/design-reviews] WebXR Raw Camera Access API (#652)

Thanks for sending this our way and thanks for documenting the user needs and filling out the security & privacy questionnaire. One question related to privacy - you note in the explainer that the feature does not currently exist due to privacy. However, when it comes to permissions you state:

> If UA decides it needs to prompt the user for permission to use the camera, it can do so at this stage.

It feels to me like this needs to be stronger. Can there be a normative requirement to seek user permission or at least stronger language to that effect? It's good that you call this out in the spec https://immersive-web.github.io/raw-camera-access/#privacy-security but likewise it feels like this should be a stronger requirement. Also it feels like there should be more in this section that enumerates abuse scenarios and how the API proposes to mitigate against these abuses.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/652#issuecomment-870408043

Received on Tuesday, 29 June 2021 08:52:47 UTC