Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

css-color-adjust-1 "forced colours mode" re-introduces a privacy concern #5548

Closed
mallory opened this issue Sep 24, 2020 · 2 comments
Closed

Comments

@mallory
Copy link

mallory commented Sep 24, 2020

I reviewed [css-color-4] and found that the deprecated systemcolors are necessarily back because of the use of forced colors mode. Even as per the current privacy and security considerations section of [css-color-adjust-1]:

{{
Applying user color preferences via color schemes or forced colors mode expose the user’s color preferences to the page, which can increase fingerprinting surface.
}}

It would be better if these were only available to the user-agent in order to do the color mapping.

[css-color-4] https://drafts.csswg.org/css-color-4/#deprecated-system-colors
[css-color-adjust-1] https://drafts.csswg.org/css-color-adjust-1/#privsec

@fantasai fantasai added css-color-4 Current Work css-color-adjust-1 Current Work labels Jan 7, 2021
@fantasai
Copy link
Collaborator

fantasai commented Jan 7, 2021

@mallory We've made some technical changes that make this more possible in #4915, however see #5710 for current discussion on this particular question.

@fantasai
Copy link
Collaborator

Closing as duplicate of #5710 (since the discussion is there).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants