<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>27168</bug_id>
          
          <creation_ts>2014-10-24 23:45:49 +0000</creation_ts>
          <short_desc>Individualization text regarding device identifiers is overbroad and should be more specific</short_desc>
          <delta_ts>2015-10-20 23:32:45 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>Encrypted Media Extensions</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>MOVED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard>Privacy</status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Joe Steele">steele</reporter>
          <assigned_to name="Adrian Bateman [MSFT]">adrianba</assigned_to>
          <cc>ddorwin</cc>
    
    <cc>mike</cc>
    
    <cc>public-html-media</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>113744</commentid>
    <comment_count>0</comment_count>
    <who name="Joe Steele">steele</who>
    <bug_when>2014-10-24 23:45:49 +0000</bug_when>
    <thetext>Section 9.4 contains the following text:

&quot;Such implementations should not use identifiers for a device or user of a device in the individualization process.&quot;

This is too broad. I proposed instead the following:
&quot;Such implementations should not directly provide identifiers for a device or user of a device in any messages sent during the individualization process.&quot;

This allows for implementations which generate unique identifiers not directly associable with the device or user by digesting a mixture of device identifiers. These identifiers can have the security property that two different devices are unlikely to generate the same identifier, but also have the privacy property that it is very difficult to match an identifier to a user+device.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>114184</commentid>
    <comment_count>1</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2014-10-28 21:11:45 +0000</bug_when>
    <thetext>I&apos;m fine with changing the text, but I think we should be more precise in what is and is not recommended. These sections contain recommendations for implementers, so we can be specific, aim high, and included the reasons and/or an analysis of such problems. Henri provides some relevant analysis in http://lists.w3.org/Archives/Public/public-html-media/2014Oct/0092.html</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>123796</commentid>
    <comment_count>2</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2015-10-20 00:26:51 +0000</bug_when>
    <thetext>Is this issue still relevant? Is there a specific suggestion addressing comment #1? If so, please open a GitHub issue. Either way, we should close this legacy bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>123797</commentid>
    <comment_count>3</comment_count>
    <who name="Joe Steele">steele</who>
    <bug_when>2015-10-20 06:11:07 +0000</bug_when>
    <thetext>Yes, this issue is still relevant. I would prefer not to be much more specific, since different implementations may use different types of identifiers. Any proprietary algorithms involved do not need to be made explicit. I can create a GitHub issue -- but it will basically just duplicate this information. Is that useful?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>123814</commentid>
    <comment_count>4</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2015-10-20 23:32:45 +0000</bug_when>
    <thetext>Migrated to https://github.com/w3c/encrypted-media/issues/110.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>