W3C home > Mailing lists > Public > public-webrtc-logs@w3.org > January 2019

Re: [mediacapture-main] Spec does no handle fingerprinting related to exposing non default capture devices (#559)

From: youennf via GitHub <sysbot+gh@w3.org>
Date: Thu, 24 Jan 2019 21:44:10 +0000
To: public-webrtc-logs@w3.org
Message-ID: <issue_comment.created-457368397-1548366248-sysbot+gh@w3.org>
> I assume we're only talking about cross-site fingerprints, because:

Cross-site fingerprinting is one concern.
https://github.com/w3c/mediacapture-main/issues/563 is another issue, non default device labels have high value and can give insights to user preferences.
Exposing the timing of plug/unplug could potentially be used to learn about user habits (big data).

> I agree this fingerprint is unreliable for a (small) sub-population who might plug/unplug USB cameras occasionally, and that sites might use _enumerateDevices()_ to update this fingerprint for this sub-population from working some of the time, to all of the time. I also agree that, these configs being rare, their fingerprinting value is higher.
> 
> Do I have the value-add right?

Agreed.
As of unreliable for a small sub-population, maybe it will increase over time (BT headset, action cameras paired to laptop that could use them as regular camera/mic) but that increases other risks.

-- 
GitHub Notification of comment by youennf
Please view or discuss this issue at https://github.com/w3c/mediacapture-main/issues/559#issuecomment-457368397 using your GitHub account
Received on Thursday, 24 January 2019 21:44:12 UTC

This archive was generated by hypermail 2.3.1 : Tuesday, 4 June 2019 15:32:54 UTC