Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Atomize information for principle of least authority #7

Closed
msporny opened this issue Nov 28, 2016 · 4 comments
Closed

Atomize information for principle of least authority #7

msporny opened this issue Nov 28, 2016 · 4 comments
Assignees
Labels
privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.
Milestone

Comments

@msporny
Copy link
Member

msporny commented Nov 28, 2016

We should include information in the spec that states that when issuing information, one should issue it in the smallest pieces possible. When requesting information, only ask for the data points that you need. Issue abstract claims alongside actual data when possible.

@msporny msporny added editorial Purely editorial changes to the specification. privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. labels Nov 28, 2016
@talltree
Copy link

Manu, what do you mean by "issue abstract claims alongside actual data"?

@dlongley
Copy link
Contributor

@talltree, I would guess that means when issuing, for example, a Passport credential with a birthdate (actual data), also issue a Proof of Age credential with an "age over 21" abstract claim.

@msporny msporny removed the editorial Purely editorial changes to the specification. label Dec 7, 2016
@David-Chadwick
Copy link
Contributor

Perhaps the spec should go even further than this, and say that when issuing credentials, if it not technically possible for the user to selectively reveal single attributes (claims) from the credential, then the issuer should issue a set of credentials, each credential containing a single attribute (claim) only. The user may then aggregate these as necessary and as required by the inspector

@msporny
Copy link
Member Author

msporny commented Feb 13, 2017

@David-Chadwick Yes, we will want to make a note of that in the privacy section.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.
Projects
None yet
Development

No branches or pull requests

5 participants