Re: Privacy considerations of persistent device keys / device IDs

>> 1) Remove the KeyStorage API [Done]
>
> No, you do not have agreement of the group to do that. Please, let's not get into HTML-WG-style revert requests. You need consensus to make changes and you clearly do not have it.

Mark,

Consensus was reached during the Face to Face, recorded in the
minutes, and reflected in the ACTION assigned to the editors -
http://www.w3.org/2012/webcrypto/track/actions/60 . That decision was
recorded, so this is not some unilateral action being taken.

Your point that removing KeyStorage prevents your particular use case
is noted. You can certainly make a proposal to provide text that
addresses your use case.

But we should not simply leave misleading or non-implemented text in
place, simply because we don't (yet) have something better, let alone
before we've agreed upon adding and addressing that feature.

For ANY feature, and not just pre-provisioned key, if there are
issues, it is BETTER to remove it from the spec and address it with
follow-up proposals than to simply leave it in place "because it's
easier" or "because it's convenient".

Received on Thursday, 8 November 2012 16:26:51 UTC