canmove, Confirmed users
1,537
edits
| (9 intermediate revisions by 2 users not shown) | |||
| Line 12: | Line 12: | ||
|'''Security Contact:''' || Curtis Koenig | |'''Security Contact:''' || Curtis Koenig | ||
|- | |- | ||
|'''Document State:''' || <section begin='status'/>{{ | |'''Document State:''' || <section begin='status'/>{{drop|postponed until 2012}}<section end='status'/> | ||
|} | |} | ||
| Line 164: | Line 164: | ||
In this section, areas of user data risk are identified and recommendations made for minimizing the risk. | In this section, areas of user data risk are identified and recommendations made for minimizing the risk. | ||
== | == Unintended Dissemination of User Data == | ||
''The Risk'' is the possibility of syncing user data to Google unexpectedly or undesirably to the user, via storing bookmarks, history, etc in the Android system store | ''The Risk'' is the possibility of syncing user data to Google or other third party services unexpectedly or undesirably to the user, via storing bookmarks, history, etc in the Android system store. The third party services mentioned here are those connected to the users' phones by installing apps that access the system store -- one of which is Google (sync). | ||
''Requirement:'' There must be explicit messaging that users may need to take action to opt out of having their Firefox for Android data synced to Google. (If they have their phone configured to sync data to Google, which many users will - the change to using system storage and its implications must be communicated loudly and clearly to avoid user surprise). | ''Requirement:'' There must be explicit messaging that users may need to take action to opt out of having their Firefox for Android data synced to Google or other third parties. (If they have their phone configured to sync data to Google, which many users will - the change to using system storage and its implications must be communicated loudly and clearly to avoid user surprise). | ||
''Recommendation:'' Provide an option to store data separate from the globally accessed store. When enabled, this feature would not use the global system services to store history, bookmarks, and passwords but instead hide them from the rest of the phone and discourage cross-app data sharing on the device. Consider this separate data store as the default storage for Firefox for Android and have users opt in to using system storage. | ''Recommendation:'' Provide an option to store data separate from the globally accessed store. When enabled, this feature would not use the global system services to store history, bookmarks, and passwords but instead hide them from the rest of the phone and discourage cross-app data sharing on the device. Consider this separate data store as the default storage for Firefox for Android and have users opt in to using system storage. | ||
{{ResolutionBox|{{ | {{ResolutionBox|{{ok| {{bug|704490}} in progress for local (non-systemwide) bookmark/history databases. Also should default to this local alternative.}}}} | ||
== Update and Profile Data Migration == | == Update and Profile Data Migration == | ||
| Line 219: | Line 219: | ||
{{ResolutionBox|{{new|}}}} | {{ResolutionBox|{{new|Address requirements and recommendations for disclosures and defaults listed above.}}}} | ||
= Follow-up Tasks and tracking = | = Follow-up Tasks and tracking = | ||
| Line 234: | Line 234: | ||
| Brief "hallway" chat. | | Brief "hallway" chat. | ||
|- | |- | ||
| {{ | | {{done|public call for comments}} | ||
| Sid | | Sid | ||
| | | | ||
| | | 7-Dec-2011 - post to dev.planning for input | ||
|- | |- | ||
| {{new|discuss recommendations with team}} | | {{new|discuss recommendations with team}} | ||
| Sid / Ian / Mobile team | | Sid / Ian / Mobile team | ||
| | | | ||
| 14-Dec or so | |||
|- | |||
| {{ok|implement separate (local) bookmark/history DBs for access by only Mozilla apps}} | |||
| Mobile team | |||
| {{bug|704490}} | |||
| TBD | |||
|- | |||
| {{new|default to local DBs for bookmarks and history, allow users to enable system storage}} | |||
| Mobile team | |||
| | |||
| TBD | |||
|- | |||
| {{new|implement opt-in migration path for sync data to local or system dbs}} | |||
| Mobile team | |||
| | |||
| TBD | | TBD | ||
|} | |} | ||
[[Category:Privacy/Reviews| | [[Category:Privacy/Reviews|AndroidSystemStorage]] | ||