Self-review of security and privacy questionnaire for 2.0 CR transition
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
- Issue type
- Documentation
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- wasm
- Domain
- documentation, security
Research direction
Start by reviewing the W3C Security and Privacy Questionnaire, the Fingerprinting Guidance, and RFC 6973 cited in the issue. Verify the paragraph-form answers against WebAssembly 2.0 and record a complete self-review for the CR transition, including whether any new security or privacy impacts exist.
Written by the indexing model from the issue text.
Description
Answers to questions to consider from https://www.w3.org/TR/security-privacy-questionnaire/
(organized into paragraph form but with references to each question in parens). https://www.w3.org/TR/fingerprinting-guidance/ and https://www.rfc-editor.org/rfc/rfc6973.html have also been consulted but do not ask specific questions.
WebAssembly provides no access to the surrounding environment other than via the JavaScript API described in the JS API specification. Therefore, WebAssembly cannot collect or expose any information (personal, sensitive or otherwise) to Web sites or other parties beyond what can be collected, exposed or processed with JavaScript (2.1, 2.2, 2.3, 2.4, 2.12). WebAssembly memory has the same lifetime as the objects in the surrounding JavaScript environment and is not persisted or serialized (other than by copying it out to JavaScript and using existing serialization APIs) (2.5). No access is provided to the underlying platform or hardware (2.7, 2.8), or to other devices (2.10), or to the user agent’s native UI (2.11).
WebAssembly is an additional program execution mechanism (2.9), and can be executed wherever JavaScript can be executed (2.13, 2.14). Therefore the threat model (3) is essentially the same as for JavaScript code, and has similar considerations for delivery (e.g. WebAssembly code should be protected in transit from active and passive network attackers) and policy (e.g. some loading mechanisms or execution are restricted via mechanisms such as the same-origin policy or Content Security Policy). Origins cannot downgrade security protections (2.16), and non-fully-active documents are handled the same as with JavaScript (2.17).
There are no known security or privacy impacts of any of the new features introduced in version 2.0. There are no new sources of nondeterminism in execution (which would be the most likely source of active fingerprinting information) and (as mentioned above) no new state or access to the underlying platform.
- Dominant language
- WebAssembly
- Stars
- 3.5k
- Forks
- 539
- Avg merge
- 10h 38m
- Merged PRs (30d)
- 12
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from WebAssembly/spec
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
WebAssembly/spec#2258 · 4 comments · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 58/100
WebAssembly/spec#2253 ·
Maintainers usually reply within 1 day
-
[spectec] Wasm 1.0: `$instantiate` missing premisesPossibly taken @rossberg claimed this 26 days ago. Open
Difficulty 3/5 1-2 days Newbie friendliness 68/100
WebAssembly/spec#2245 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 45/100
WebAssembly/spec#2235 · 9 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
WebAssembly/spec#2196 ·
Maintainers usually reply within 1 day
All issues in WebAssembly/spec
Similar issues
-
C-bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 2 days
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
bojieli/ai-agent-book#1169 ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
githubnext/gh-aw-workshop#4216 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
ehmpathy/rhachet-roles-bhrain#572 ·
Maintainers usually reply within 1 day
-
sync-en
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day