[All Lists] [By Thread] [By Date] [Previous] [Next]


From: R. Feldman
Subject: Registry concerns
Date: 19 Shevat 5781


Subject: Proposed language

The committee has had a difficult but necessary discussion. I propose we address these concerns in the specification itself.

Draft language for the Security Considerations section:

Identity blocks are self-attested and unverified. They MUST NOT be used as the sole basis for authorization decisions. They MUST NOT be treated as proof of Jewish status.

And additional language:

Systems processing identity blocks should consider the sensitivity of aggregated identity data. Implementations SHOULD minimize data retention. Implementations SHOULD NOT maintain centralized registries of identity blocks or their hashes beyond what is necessary for immediate function.

I invite comment on this language.


Thread:

[Previous] [Next]


DEP Discussion Archives
https://dep-specs.org/