W3C home > Mailing lists > Public > public-webauthn@w3.org > September 2017

Re: [webauthn] imageURL privacy

From: Angelo Liao via GitHub <sysbot+gh@w3.org>
Date: Fri, 15 Sep 2017 21:27:50 +0000
To: public-webauthn@w3.org
Message-ID: <issue_comment.created-329908365-1505510860-sysbot+gh@w3.org>
@leshi  From what I read, the account chooser UI is better because it incorporates the image. @selfissued and other identity folks can comment more on the UI. 

I am not sure if we are actually gaining privacy. At the end of the day, image is just another piece of data. The RP already supplies the name of the user, which can be used to identify the user. Comparatively image is probably more difficult to be use for privacy attacks. In the meantime, adding icon adds a lot of UX improvement (from what I heard). 


-- 
GitHub Notification of comment by AngeloKai
Please view or discuss this issue at https://github.com/w3c/webauthn/issues/139#issuecomment-329908365 using your GitHub account
Received on Friday, 15 September 2017 21:27:42 UTC

This archive was generated by hypermail 2.4.0 : Tuesday, 5 July 2022 07:26:27 UTC