Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Who is assumed to have access to first and delegated party assets? #19

Open
eriktaubeneck opened this issue Oct 21, 2022 · 1 comment
Open

Comments

@eriktaubeneck
Copy link
Collaborator

I know that this is unchanged, but I'm going to open an issue about this one. I find this a little unclear as presented here.

Is this all first and third parties? I think that - for threat model purposes - we might assume that this is indeed all information from all sites, but that might be a little over-broad.

Also, I'd like to see us talk about sites rather than parties. Even if we need to acknowledge that apps are not web sites, they should follow roughly similar rules when it comes to their composition.

Originally posted by @martinthomson in #14 (comment)

@eriktaubeneck
Copy link
Collaborator Author

I certainly agree there is some work to do here. I think the idea was that we want to assume that an attacker might not only control some number of helper parties, but also a first or third party (this should also now be delegated party...). From there, we basically assume that the helper party could also have the first/delegated party assets. But, yes, a new issue for this would be great. I would love to get more input here.

I'm unopinionated on party vs site (though maybe we want to use site/app to be explicit.) I'll open a PR with that swap and try to get some input.

Originally posted by @eriktaubeneck in #14 (comment).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant