Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

How can clients verify that a device they're interacting with is compliant? #385

Open
pes10k opened this issue Mar 29, 2023 · 1 comment
Labels
needs discussion privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. Profile-1.0

Comments

@pes10k
Copy link

pes10k commented Mar 29, 2023

This issue is being filed as part of the requested PING review, and on behalf of @NalaGinrut who did the review (who i hope will correct me if I've misstated their concerns).

The spec currently states that

Whether or not a TD satisfies the requirements of a given profile should be verifiable with automated tools. We can use the existing TD JSDON Schema as a basis and reuse the existing tooling (TD-playground)

However, its not clear how a client could verify that a TD is compliant and honest in its claims. What methods can a client, for example, use to ensure a device they're interacting with isn't being deceptive or malicious? If thats not possible, we think its important to say so explicitly in the security and privacy considerations section (i.e., that the protections require honesty, and are not robust to malicious/dishonest devices/participants)

@pes10k pes10k added the privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. label Mar 29, 2023
@pes10k
Copy link
Author

pes10k commented Mar 29, 2023

again cc @NalaGinrut (though please let me know if i can help with discussion or handling this issue)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs discussion privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response. Profile-1.0
Projects
None yet
Development

No branches or pull requests

3 participants