<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>27165</bug_id>
          
          <creation_ts>2014-10-24 21:38:57 +0000</creation_ts>
          <short_desc>User agents should warn users if they bring along unclearable identifiers</short_desc>
          <delta_ts>2014-12-09 00:35:00 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>Encrypted Media Extensions</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>Windows NT</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard>Privacy, TAG</status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Domenic Denicola">d</reporter>
          <assigned_to name="David Dorwin">ddorwin</assigned_to>
          <cc>ddorwin</cc>
    
    <cc>mike</cc>
    
    <cc>public-html-media</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>113736</commentid>
    <comment_count>0</comment_count>
    <who name="Domenic Denicola">d</who>
    <bug_when>2014-10-24 21:38:57 +0000</bug_when>
    <thetext>As discussed in http://lists.w3.org/Archives/Public/www-tag/2014Oct/0106.html, some DRM implementations---for Silverlight, at least---bring along semi-permanent client IDs.
 
We should consider requiring or strongly recommending that user agents prompt or inform the user if an EME implementation brings along identifiers that cannot be cleared along with regular cookies and site data (similar to Mark’s “more privacy sensitive than regular cookies” bar).

I will file a separate bug exploring whether we can require that such identifiers be clearable, but we can use this bug to discuss mitigation strategies if they must be unclearable for robustness reasons.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>116033</commentid>
    <comment_count>1</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2014-12-09 00:35:00 +0000</bug_when>
    <thetext>Implemented in https://github.com/w3c/encrypted-media/commit/3ead3c182ac6cd75a0ab77e2bcb957c09cdea006

Note: The separate bug referenced in comment #0 is bug 27166.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>