Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Should the allowlist be explicitly public? #1

Open
Sauski opened this issue Oct 10, 2024 · 1 comment
Open

Should the allowlist be explicitly public? #1

Sauski opened this issue Oct 10, 2024 · 1 comment

Comments

@Sauski
Copy link

Sauski commented Oct 10, 2024

The list of sites which are provided this information is a key mitigation against abuse - I would expect that such a list is publicly auditable to ensure it is actually achieving that mitigation.

There is some prior art in this space, with the list of Related Website Sets and Private State Token issuers publicly available.

@eladalon1983
Copy link
Contributor

Thanks, these are great precedents, and will come in very useful!

Do you happen to know if there might also be precedents of such lists, which are used (and possibly also maintained) by multiple browsers?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants