Skip to content

Conversation

@simoneonofri
Copy link
Contributor

@simoneonofri simoneonofri commented Jan 8, 2026

Security mitigations - Error Messages Normalization

For more context, please refer to the Google Doc containing the Threat Model (which will be published as separate Notes) and the complete Section.

Closes #???

The following tasks have been completed:

  • Modified Web platform tests (link)

Implementation commitment:

  • WebKit (link to issue)
  • Chromium (link to issue)
  • Gecko (link to issue)

Documentation and checks

  • Affects privacy
  • Affects security
  • Pinged MDN
  • Updated Explainer
  • Updated digitalcredentials.dev

Preview | Diff

Security mitigations - Error Messages Normalization

For more context, please refer to the [Google Doc](https://docs.google.com/document/d/1BpBBiv7GgkGi1_Y7NvyD3Mkalj0g857Qw-aan3NqYwU/edit?tab=t.dilz864boly) containing the Threat Model (which will be published as separate Notes) and the complete Section.
<h4>Error Messages Normalization</h4>
<p>The specification normalizes error messages for the implementation, returning the same error for both
“user declined” and “no credentials exist”.</p>
<p>This reduces the browser fingerprinting (threat shared with Privacy) by preventing the user agent from disclosing specific
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
<p>This reduces the browser fingerprinting (threat shared with Privacy) by preventing the user agent from disclosing specific
<p>This reduces browser fingerprinting (threat shared with Privacy) by preventing the user agent from disclosing specific

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants