Privacy/Reviews/F1A: Difference between revisions

Line 485: Line 485:
''The Risk:'' the user will knowingly provide third parties with insight into what sites they've visited in the past.  Browsing history is generally considered to be private, and the disclosure of such data should be calculated.  This is a very tiny risk since the whole point of this feature is to share URLs.  Nonetheless, the risk is there and unless the user is always at the helm when data sharing happens, it could be leaked without consent.
''The Risk:'' the user will knowingly provide third parties with insight into what sites they've visited in the past.  Browsing history is generally considered to be private, and the disclosure of such data should be calculated.  This is a very tiny risk since the whole point of this feature is to share URLs.  Nonetheless, the risk is there and unless the user is always at the helm when data sharing happens, it could be leaked without consent.


URLs shortened through a URL shortening service are disclosed to that service.  If URL shortening services are used, it must be clear what is happening.
URLs shortened through a URL shortening service are disclosed to that service.  If third-party URL shortening services are used (shorteners not part of the service used for sharing), it must be clear what is happening.


''Requirement:'' The UI must clearly show each URL being shared and with which parties the URL will be shared before it is transmitted.  If URL shortening is used, there must be user intervention before the URL is sent to the service for shortening.  (UI can be used to "remember" the user's preference to shorten URLs, but that must be opt-in).   
''Requirement:'' The UI must clearly show each URL being shared and with which parties the URL will be shared before it is transmitted.  If an additional URL shortening service is used, there must be user intervention before the URL is sent to the service for shortening.  (UI can be used to "remember" the user's preference to shorten URLs, but that must be opt-in).   


{{ResolutionBox|{{ok|UI is clear about with whom users are sharing URLs.  Twitter uses bit.ly shortening on the server-side (their end).  This should be made clear in the UI so users know bit.ly will learn the URL.  bit.ly does not learn the URL before "share" is clicked.}}}}
{{ResolutionBox|{{resolved|UI is clear about with whom users are sharing URLs.  Twitter uses its own in-house shortening on the server-side (their end).}}}}


=Conformity to Private Browsing Mode (If Applicable)=
=Conformity to Private Browsing Mode (If Applicable)=
canmove, Confirmed users
1,537

edits