Privacy/Reviews/AndroidSystemStorage: Difference between revisions

m
 
(4 intermediate revisions by 2 users not shown)
Line 12: Line 12:
|'''Security Contact:''' || Curtis Koenig
|'''Security Contact:''' || Curtis Koenig
|-
|-
|'''Document State:''' || <section begin='status'/>{{ok|in risk analysis}}<section end='status'/>
|'''Document State:''' || <section begin='status'/>{{drop|postponed until 2012}}<section end='status'/>
|}
|}


Line 166: Line 166:
== Unintended Dissemination of User Data ==
== Unintended Dissemination of User Data ==


''The Risk'' is the possibility of syncing user data to Google unexpectedly or undesirably to the user, via storing bookmarks, history, etc in the Android system store
''The Risk'' is the possibility of syncing user data to Google or other third party services unexpectedly or undesirably to the user, via storing bookmarks, history, etc in the Android system store.  The third party services mentioned here are those connected to the users' phones by installing apps that access the system store -- one of which is Google (sync).


''Requirement:'' There must be explicit messaging that users may need to take action to opt out of having their Firefox for Android data synced to Google. (If they have their phone configured to sync data to Google, which many users will - the change to using system storage and its implications must be communicated loudly and clearly to avoid user surprise).
''Requirement:'' There must be explicit messaging that users may need to take action to opt out of having their Firefox for Android data synced to Google or other third parties. (If they have their phone configured to sync data to Google, which many users will - the change to using system storage and its implications must be communicated loudly and clearly to avoid user surprise).


''Recommendation:'' Provide an option to store data separate from the globally accessed store.  When enabled, this feature would not use the global system services to store history, bookmarks, and passwords but instead hide them from the rest of the phone and discourage cross-app data sharing on the device. Consider this separate data store as the default storage for Firefox for Android and have users opt in to using system storage.
''Recommendation:'' Provide an option to store data separate from the globally accessed store.  When enabled, this feature would not use the global system services to store history, bookmarks, and passwords but instead hide them from the rest of the phone and discourage cross-app data sharing on the device. Consider this separate data store as the default storage for Firefox for Android and have users opt in to using system storage.


{{ResolutionBox|{{ok| {{bug|704490}} in progress for local (non-systemwide) bookmark/history databases. Also should default to this local alternative.}}}}
{{ResolutionBox|{{ok| {{bug|704490}} in progress for local (non-systemwide) bookmark/history databases. Also should default to this local alternative.}}}}
: [[User:LawrenceMandel|LawrenceMandel]] I think there is an additional concern that another app (perhaps another browser with a sync feature) may also read from the system store and disseminate user data. In this situation opting out of Google sync is not enough to protect the user.


== Update and Profile Data Migration ==
== Update and Profile Data Migration ==
Line 236: Line 234:
| Brief "hallway" chat.
| Brief "hallway" chat.
|-
|-
| {{new|public call for comments}}
| {{done|public call for comments}}
| Sid
| Sid
|  
|  
Line 263: Line 261:




[[Category:Privacy/Reviews|Template]]
[[Category:Privacy/Reviews|AndroidSystemStorage]]
canmove, Confirmed users
1,537

edits