Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Describe more privacy mitigations #167

Open
jyasskin opened this issue Dec 6, 2019 · 0 comments
Open

Describe more privacy mitigations #167

jyasskin opened this issue Dec 6, 2019 · 0 comments

Comments

@jyasskin
Copy link
Member

jyasskin commented Dec 6, 2019

https://wicg.github.io/BackgroundSync/spec/PeriodicBackgroundSync-index.html#privacy should describe how browsers might protect users from the privacy risks. The current location tracking section suggests limiting the number of data points the site gets, but it doesn't suggest any ways to get the number down to 0. Possible ways to eliminate IP-based geolocation might include:

History leaks to the network the user happens to be on when a background sync happens are also blocked by either Tor or a VPN. The VPN still learns about the traffic, which might be an issue and should be mentioned in the Privacy Considerations section. We're also making some progress eliminating the DNS and SNI leaks: maybe background syncs should only happen when DoT/DoH and eSNI are enabled, and the DoT/DoH server is one of the ones used when the user intentionally visited the site? This still leaves information leaked by the target site's IP address, which can be identifying for sites not behind CDNs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant