-
Notifications
You must be signed in to change notification settings - Fork 47
Open
Labels
PrivacySecurityprivacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.security-trackerGroup bringing to attention of security, or tracked by the security Group but not needing response.Group bringing to attention of security, or tracked by the security Group but not needing response.tag-trackerGroup bringing to attention of the TAG, or tracked by the TAG but not needing response.Group bringing to attention of the TAG, or tracked by the TAG but not needing response.
Description
Investigation
Abstract: digital credentials, particularly for the use of high-assurance, government-issued credentials, present opportunities for authenticated high-assurance online interactions, but also serious risks to human rights, including privacy and free expression.
What would this work do if successful?
- assess societal and human rights impacts, and set guidelines for future work
- develop threat model, harms model and potential mitigations
- coordinate design of architectural protections in Recommendation-track deliverables
- provide recommendations for the development and deployment of high assurance credentials systems by governments/industry
- review deliverables, during wide review and during deployment/adoption
Who would be interested/supportive?
- credentials-related Working Groups and Community Groups
- review groups (including at least PING and TAG)
- experts in privacy, free expression and human rights
- ...
Next steps
- Identify where this work should take place, with options including: a TAG-convened Task Force; committed deliverables within Working Groups working on credentials specs; the Privacy Working Group/PING; a new Credentials Interest Group.
- Define a scope of work, in a separate charter or the charters of related groups.
- Review by the Advisory Committee, in charters, discussion at TPAC, or separate ad-hoc meetings.
This continues a discussion that has been happening:
- 2024 Hiroshima AC meeting (Identity on the Web, follow-up breakout session)
- Adding Digital Credentials to FedID WG
- TAG Privacy Principles Task Force discussion
- PING credential-considerations repo
jyasskin, msporny, chrisn, aniltj and simoneonofri
Metadata
Metadata
Assignees
Labels
PrivacySecurityprivacy-trackerGroup bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.security-trackerGroup bringing to attention of security, or tracked by the security Group but not needing response.Group bringing to attention of security, or tracked by the security Group but not needing response.tag-trackerGroup bringing to attention of the TAG, or tracked by the TAG but not needing response.Group bringing to attention of the TAG, or tracked by the TAG but not needing response.