Skip to content

Limiting capability of RenderCapacity API in inactive tabs #2536

@hoch

Description

@hoch

During the development in Chrome, some privacy concerns were raised about RenderCapacity API:

My concern is that two tabs receive the same change in buckets at the same time (in this sense, the number of buckets is somewhat irrelevant). This would allow them to, outside the browser, compare timestamps.

The reference: https://github.com/asankah/ephemeral-fingerprinting#limit-api-access-to-focused-top-level-browsing-context

I am curious what other WG members think.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions