-
Notifications
You must be signed in to change notification settings - Fork 22
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Updates to "Security and Privacy Guidelines" (omnibus) #209
Comments
Some things I noticed need fixing:
|
|
Discussion in Security TF call Jan 30:
|
Other:
|
Additional comments:
to
as the types of credentials described above are nothing to do with access control. |
Survey of Risks mentioned in various deliverables - we should make sure these are consistent with the Threats in the guidelines document (at least one is missing, DDoS): Discovery:
Thing Description
Architecture
|
Test link to threat in S&P Guidelines: https://w3c.github.io/wot-security/#dfn-malicious-authorized-solution-user |
Factor out the above survey of considerations in to a separate file: #233 |
Close this issue, but factor out into other small issues. A number of the things discussed here have already been taken care of. Above PR captures survey. Here is a consolidated list of all the discussion points that have not yet been addressed or for which an issue has not be created:
Will create one issue just for these points, close this issue. Here are some points we have outstanding issues for:
Here are some points that we have already addressed:
|
content has been reorganized into other issues/PRs. |
The "Security and Privacy Guidelines" document has not been updated for a couple years and should be to take account of the new assertions in the new deliverables, and the removal of the Best Practices document (see Issue #208).
See also See also TAG Review of Architecture
The text was updated successfully, but these errors were encountered: