indieweb / indieweb/indieauth

IndieAuth needs non-normative Privacy Threat Model documentation

Open
#63 0 comments 3 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
57
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Similar to [The Google WebID privacy threat model document](https://github.com/WICG/WebID/blob/master/privacy_threat_model.md), the IndieAuth specification should have a brief non-normative “Privacy Threat Model” or “Privacy Considerations” section, perhaps right after the [Security Considerations](https://indieauth.spec.indieweb.org/#security-considerations) section, or alternatively as a separate document which the spec links to.

(Originally published at: https://tantek.com/2020/286/b1/)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the IndieAuth specification's Security Considerations section and the linked Google WebID privacy threat model. Define the relevant privacy threats in a brief non-normative Privacy Threat Model or Privacy Considerations section, or a separate document linked from the specification; done means the privacy guidance is published in one of those forms.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.