Skip to content

Commit

Permalink
Merge pull request w3c#1765 from w3c/issue-1763-uv-pii
Browse files Browse the repository at this point in the history
Clarify why PII is not allowed in user handle
  • Loading branch information
emlun authored Jul 13, 2022
2 parents f3d4a9a + be456bd commit 8f5b772
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion index.bs
Original file line number Diff line number Diff line change
Expand Up @@ -7615,7 +7615,9 @@ only to the operating system user that created that [=platform credential=].

### User Handle Contents ### {#sctn-user-handle-privacy}

Since the [=user handle=] is not considered [PII] in [[#sctn-pii-privacy]], the [=[RP]=] MUST NOT include [PII], e.g., e-mail
Since the [=user handle=] is not considered [PII] in [[#sctn-pii-privacy]],
and since [=authenticators=] MAY reveal [=user handles=] without first performing [=user verification=],
the [=[RP]=] MUST NOT include [PII], e.g., e-mail
addresses or usernames, in the [=user handle=]. This includes hash values of [PII], unless the hash
function is [=salted=] with [=salt=] values private to the [=[RP]=], since hashing does not prevent probing for guessable input
values. It is RECOMMENDED to let the [=user handle=] be 64 random bytes, and store this value in the [=user account=].
Expand Down

0 comments on commit 8f5b772

Please sign in to comment.