graphic with four colored squares

Permissions for Web Applications

W3C TAG F2F, Jan 8

Dominique Hazaël-Massieux

HTML5 Apps EU project This project is funded by the European Union through the Seventh Framework Programme (FP7/2013-2015) under grant agreement n°611327 - HTML5 Apps

Web Apps / Native Apps

Reasons for doing native over Web:

Hardware/device integration

Two approaches

APIs

New hardware/device APIs bring new risks:

Privacy risks: Data leakage

→ Gate access to privacy sensitive APIs

Privacy risks: Fingerprinting

Privacy risks: Context Leakage

Security risks

UI mitigation

Designing new APIs

Web APIs model

Uncoordinated approaches

Review of existing APIs and permission models

How others do?

Extending Trusted Apps model to the Web

→ change the model of the Web

Previous W3C work in this space

What do we need?

Potential role of the TAG