- From: Peter Linss <notifications@github.com>
- Date: Wed, 06 Sep 2023 23:50:31 -0700
- To: w3ctag/design-reviews <design-reviews@noreply.github.com>
- Cc: Subscribed <subscribed@noreply.github.com>
Received on Thursday, 7 September 2023 06:50:37 UTC
We haven't had a chance to dive into this thoroughly yet, but first impressions: * The term "entropy" has a number of other connotations and may not be the best term here. Possibly something like "systemLoad" might be more obvious to users. * I don't have specific examples, but this leads to concern about possibly introducing additional information for side-channel attacks or user fingerprinting (see battery status API). I accept that this is past data, but it's strongly correlated with high resolution timers. Have crypto and privacy experts evaluated this aspect? -- Reply to this email directly or view it on GitHub: https://github.com/w3ctag/design-reviews/issues/878#issuecomment-1709572971 You are receiving this because you are subscribed to this thread. Message ID: <w3ctag/design-reviews/issues/878/1709572971@github.com>
Received on Thursday, 7 September 2023 06:50:37 UTC