Comments (4)
Ok, we can add some normative guidance noting that verifiers SHOULD cache the result.
from vc-bitstring-status-list.
The issue was discussed in a meeting on 2024-03-13
- no resolutions were taken
View the transcript
2.1. caching status lists as a mitigation for identifying when the holder visited a verifier (issue vc-bitstring-status-list#144)
See github issue vc-bitstring-status-list#144.
Manu Sporny: PING wants normative guidance on caching behavior on status list.
Dmitri Zagidulin: (yeyyy normative guidance!).
Manu Sporny: if we put MUST we need to test it; Not sure how we would test it in this group.
… best we can say is SHOULD cache rather than MUST.
Dave Longley: +1 to SHOULD.
Dmitri Zagidulin: +1 to SHOULD.
Manu Sporny: would prefer SHOULD.
Brent Zundel: why don't we simply ask implementers whether they do cache. It is lame test, but may work.
Ivan Herman: agree with you. The goal of testing is to see if the recommendation is implementable...
Brent Zundel: other comments on this issue?
Manu Sporny: Fine, but concerned with precedent.
… Maybe the way we implement this is to add a field to each implementations implementation config file... "iCacheStatusListsISwear": true.
Brent Zundel: I hear the concerned. This group has had a commitment to developing solid test suites. I think we are okay.
Manu Sporny: I agree with Brent's analysis.
Paul Dietrich: arguing MUST may be too restrictive.
Manu Sporny: I also agree with Paul's concern.
Dave Longley: "yes, my implementation caches when
validUntil
is present".
Brent Zundel: editors of bitstring stat list, do you have what you need?
Manu Sporny: yes.
Dave Longley: +1 to pauld_gs1's concerns, i think we don't want to lock in caching rules either.
Dave Longley: (i.e., it would be good to allow better caching rules over time with experience).
Manu Sporny: I'll take a shot at caching rules, with a MUST and otherwise will backoff to a SHOULD.
Brent Zundel: could have a MUST with recommended caching rules.
Dave Longley: +1 to something like what Brent said around caching rules.
from vc-bitstring-status-list.
Related Issues (20)
- Add `@type` to `encodedList` term definition HOT 4
- "bitstring" vs "bit string" HOT 4
- Accessibility self-review of Bitstring Status List v1.0
- Internationalization Self-Review for Bitstring Status List v1.0
- Horizontal Reviews for Bitstring Status List v1.0 HOT 1
- Encoding of `statusListIndex` HOT 3
- `statusPurpose` type `message` unclear HOT 2
- `credentialSubject.statusMessage` localizable? HOT 3
- Processing error `title` and `detail` need lang/dir guidance HOT 5
- Testing with revoked and not-revoked credential HOT 1
- status list index is a persistent cross-origin identifier HOT 4
- mitigations for risk of unique status lists HOT 4
- anonymizing proxy rather than CDN as a privacy mitigation HOT 4
- information revealed by status updates HOT 6
- when revocation status is and isn't appropriate to present HOT 3
- comparison with alternative revocation mechanisms HOT 3
- status list index randomization requirement HOT 3
- Describe decoy entries as a privacy mitigation HOT 7
- Remove open ended status messages because it is a layer violation HOT 10
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from vc-bitstring-status-list.