Skip to content
This repository has been archived by the owner on Mar 16, 2023. It is now read-only.

PING Privacy Review: Determining "Sensitive Cohorts" #71

Open
kdeqc opened this issue Mar 18, 2021 · 4 comments
Open

PING Privacy Review: Determining "Sensitive Cohorts" #71

kdeqc opened this issue Mar 18, 2021 · 4 comments

Comments

@kdeqc
Copy link

kdeqc commented Mar 18, 2021

We had a lot of questions about how "sensitive cohorts" will be identified, and how this will be monitored. One concern is how this will be handled geographically, since what is considered sensitive can change from region to region. We also wondered if there were any considerations for user controls here too.

@jkarlin
Copy link
Collaborator

jkarlin commented Mar 18, 2021

We're preparing a document that we'll place on this repo that describes how Chrome ensures that cohorts do not reveal sensitive information. Hopefully that will be published soon.

@skaurus
Copy link

skaurus commented Mar 18, 2021

I imagine that users could opt-in on each site to allow their visits to that site to participate in cohort discovery.
A browser could ask a user about that, say after the user visited that site a few times in some period of time.

Also in that case browser could show an icon near an URL, like a https icon or camera/mic permissions icon, so the user can revoke his permission.

@kuro68k
Copy link

kuro68k commented Mar 27, 2021

It's not just that single categories are sensitive, it's also that combinations can be sensitive even if each single interest by itself is not. It will be interesting to see how such sensitive inferences are detected and handled by Chrome.

@dmarti
Copy link
Contributor

dmarti commented Apr 10, 2021

Membership in a sensitive cohort of users is not necessarily correlated with visits to sensitive sites.

  • Elementary school sites can be completely non-sensitive, but visits to school sites in a school district where segregation is a problem could reveal likely membership in a sensitive cohort.

  • Sites that have content written in language A and local sites for residents of country B could both be non-sensitive, but the cohort made up of people who use language A in country B could be sensitive.

Related issue: This proposal should define what is meant by a "sensitive category"

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants