Re: [w3ctag/design-reviews] FYI Private State Token API Permissions Policy Default Allowlist Wildcard (Issue #990)

We discussed this in a breakout and have a couple concerns:
  
* This change increases the by-default exposure of the page to entities that might "use up" its limit of 2 issuers. You've suggested that the top-level page should call the API to explicitly pick its issuers, before allowing 3p script to run. We're skeptical that that's a practical defense. You're right that it's a pre-existing issue with the API, but because this change makes the risk worse, it would be good to improve the defense before making this change.
  
* We're not the right body to judge whether the privacy implications are reasonable. Could you ask the Privacy WG to review this system?

-- 
Reply to this email directly or view it on GitHub:
https://github.com/w3ctag/design-reviews/issues/990#issuecomment-2430438460
You are receiving this because you are subscribed to this thread.

Message ID: <w3ctag/design-reviews/issues/990/2430438460@github.com>

Received on Tuesday, 22 October 2024 22:33:10 UTC