-
Notifications
You must be signed in to change notification settings - Fork 37
Wrote initial Privacy Considerations #187
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't think this is sufficient.... even as a starting point....
|
These are some things I can come up with that we should discuss in this section:
|
|
As the Privacy section is still not there for ID-1, in my opinion it would look better to leave it open and add a more thorough/completed version for the next ID-2. |
|
@selfissued below a markdown table with the articles taken from the revision text of the eIDAS regulation that can be relevant for the privacy considerations in the current specs.
|
awoie
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, an improvement to the current status.
|
@cobward made a comment that a lot in the section feels like it is about verification, not issuance. |
|
please capitalize terms, endpoints, etc. |
Co-authored-by: Gabe <7622243+decentralgabe@users.noreply.github.com>
decentralgabe
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
looks great
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM apart for one typo
Co-authored-by: Jacob <jacob.ward@spruceid.com>
Co-authored-by: Joseph Heenan <joseph@heenan.me.uk>
Sakurann
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I started reviewing this PR, but there was so much more that I believe needs to be added to be actionable to the implementers and convey to the readers how serious we are about privacy, so prepared an alternative PR #244. would appreciate the review.
| Privacy harms can occur if information about a person is released to another party without the person's consent. | ||
| True consent involves both the person knowing what information is being released and knowing who it is being released to, and for what purpose. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
it is not clear who needs to obtain consent from the end-user - issuer? wallet?
release is not really the term we have used in VCI.
| Another possibility is issuing Credentials containing only a single claim each. | ||
|
|
||
| Furthermore, multiple seemingly innocent consenting information releases can result in privacy erosion through collusion and correlation. | ||
| There may be unintended second or third order effects, which is why minimal disclosure is crucial. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
what "second or third order effects" do you mean? it is not actionable without details.
| Claims that are always disclosed can enable correlation by verifiers. | ||
| Another possibility is issuing Credentials containing only a single claim each. | ||
|
|
||
| Furthermore, multiple seemingly innocent consenting information releases can result in privacy erosion through collusion and correlation. | ||
| There may be unintended second or third order effects, which is why minimal disclosure is crucial. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
it feels like the warning against correlation and minimal disclosure are being mixed up.
|
PR #244 merged |
TBD -> actual text!