Confirmed users
3,727
edits
No edit summary |
|||
Line 246: | Line 246: | ||
= Open Questions/Issues = | = Open Questions/Issues = | ||
# How do we verify this statement: "Unlike other sign-in systems, BrowserID does not leak information back to any server (not even to the BrowserID servers) about which sites a user visits." Could use some help from Dev and PM on testable use cases. | |||
# How does this site/technology fit in? Or is it not applicable to our weekly testing? | |||
http://people.mozilla.com/~faaborg/files/projects/firefoxAccount/index.html | http://people.mozilla.com/~faaborg/files/projects/firefoxAccount/index.html | ||
# Is there any benefit to testing/comparing BrowserID with OpenID or any other ID mechanism? | |||
# Where is local storage for BrowserID? What data is stored per browser/profile/account/user? | |||
# What is the best way to approach security and privacy testing? Through the UI? through the API? Or, by setting up some unsecure environment or hackable instance? | |||
# Is it possible to have multiple accounts referencing the same email(s)? | |||
# What about multiple accounts per user (for work/prof/public emails vs. private/personal emails)? | |||
# Do we need to test/verify deviations from the standard VEC? |