<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>27270</bug_id>
          
          <creation_ts>2014-11-07 12:19:00 +0000</creation_ts>
          <short_desc>Normatively require distinctive identifiers to be forgettable/regeneratable</short_desc>
          <delta_ts>2014-12-01 18:46:45 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>HTML WG</product>
          <component>Encrypted Media Extensions</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>27166</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard>Privacy</status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>27268</dependson>
    
    <dependson>27269</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Henri Sivonen">hsivonen</reporter>
          <assigned_to name="Adrian Bateman [MSFT]">adrianba</assigned_to>
          <cc>annevk</cc>
    
    <cc>b.lund</cc>
    
    <cc>ddorwin</cc>
    
    <cc>glenn</cc>
    
    <cc>mike</cc>
    
    <cc>public-html-media</cc>
          
          <qa_contact name="HTML WG Bugzilla archive list">public-html-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>114645</commentid>
    <comment_count>0</comment_count>
    <who name="Henri Sivonen">hsivonen</who>
    <bug_when>2014-11-07 12:19:00 +0000</bug_when>
    <thetext>In order to give users the opportunity to cause a discontinuity in the ability of a site, third parties who scripts the site includes or a network MITM who injects EME usage into a non-https site to track the user across time, please require that distinctive identifiers be forgettable and regeneratable.

(Start proposed spec text for a *normative* section) 

Implementations MUST ensure that the user may request distinctive identifiers to be forgotten such that new different distinctive identifiers are generated in the place of the old ones when distinctive identifiers are needed subsequently. It is RECOMMENDED that users be able to request that distinctive identifiers be forgotten on a per-site basis, particularly as part of a &quot;Forget about this site&quot; feature that forgets cookies, databases, etc. associated with a particular site in an operation that is sufficiently atomic to prevent &quot;cookie resurrection&quot; type of recorrelation of a new identifier with the old by relying on another type of locally stored data that did not get cleared at the same time.

Note: The most obvious way to meet this requirement is to ensure that the salt contemplated in the above note (actually in bug 27269) be forgettable such that a new salt is randomly generated when needed.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>114663</commentid>
    <comment_count>1</comment_count>
    <who name="Glenn Adams">glenn</who>
    <bug_when>2014-11-07 15:13:29 +0000</bug_when>
    <thetext>I oppose adoption of this proposal due since it would dictate policy for the use of EME, which IMO is the prerogative of users of EME, and not the EME specification. In other words, I believe EME should restrict itself to defining mechanism, and not policy. If it is desirable to define a normative policy or set of policies that can be optionally adopted for standardized uses by some EME user, then such policy(ies) may be defined in a separate document and adopted (or not) by EME users as they see fit.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>114765</commentid>
    <comment_count>2</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2014-11-10 22:54:33 +0000</bug_when>
    <thetext>We also have bug 27166. Maybe we should merge the two, possibly moving the proposed text from comment #0 there.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>115743</commentid>
    <comment_count>3</comment_count>
    <who name="David Dorwin">ddorwin</who>
    <bug_when>2014-12-01 18:46:45 +0000</bug_when>
    <thetext>I copied the original description to bug 27166. We&apos;ll continue the discussion and work there.

*** This bug has been marked as a duplicate of bug 27166 ***</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>