Skip to content

Update Protection to clarify user control and access protection #9

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 10 commits into
base: main
Choose a base branch
from

Conversation

csarven
Copy link
Member

@csarven csarven commented Feb 17, 2025

This PR refines common protections expected from a user agent and clarifies considerations around user consent.


Preview | Diff

@csarven csarven force-pushed the user-control-access-protection branch from 7ee6300 to 0e52237 Compare February 17, 2025 19:18
Copy link
Contributor

@jyasskin jyasskin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not sure this does clarify things. A couple TAGs ago produced https://github.com/w3ctag/process/blob/master/style-guide.md to guide what we write, and following it is the hardest thing about writing TAG documents. Ethical Web Principles succeeds, I think, and the Privacy Principles fail. I've left some comments about the detailed wording, but maybe we should step back and think about what problems you're trying to fix with this change?

@csarven csarven force-pushed the user-control-access-protection branch from 2b76aa5 to a54d0b5 Compare March 1, 2025 23:55
@csarven csarven requested a review from jyasskin March 2, 2025 01:24
Specifically, visiting a page must not allow it to make changes to the user's computer or environment,
such as installing software, accessing hardware,
or exposing sensitive information without clear user intent.
Additionally, user agents must prevent web pages from tracking individuals unless they have explicitly enabled it.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New pgf here for the new concept? Privacy and host security are pretty distinct ideas. I'd almost reorder the entire section on that basis (deal with host security stuff with pgf 1 part 1 and pgf 3; then deal with privacy with pgf 1 part 2 and pgf 2...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants