Skip to content

[mediaqueries-5] Consider specifying privacy guidelines for user agents which automatically toggle prefers-color-scheme based on user location data #4404

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
Ajedi32 opened this issue Oct 9, 2019 · 0 comments
Labels
mediaqueries-5 privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.

Comments

@Ajedi32
Copy link

Ajedi32 commented Oct 9, 2019

Currently, the Media Queries Level 5 spec has this to say about the conditions a user agent may decide to take into account when determining what value to use for prefers-color-scheme:

The method by which the user expresses their preference can vary. It might be a system-wide setting exposed by the Operating System, or a setting controlled by the User Agent.

One common use case I've seen pop up lately is users wanting their system-wide dark mode setting to automatically toggle based on location-dependent data, such as the position of the sun relative to their current geolocation (i.e. they want to automatically turn on "dark mode" at dusk). If implemented naively without taking privacy into account, such a feature combined with prefers-color-scheme could potentially reveal the user's longitude to all websites with a remarkable degree of precision. (Multiple readings over the course of a year might also be able to determine latitude to some extent.)

In my opinion, this particular privacy concern seems both common enough and significant enough that it may be worth calling out explicitly in the spec to ensure it is properly addressed by user agents which choose to implement that feature.

This is also related to #3488

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
mediaqueries-5 privacy-tracker Group bringing to attention of Privacy, or tracked by the Privacy Group but not needing response.
Projects
None yet
Development

No branches or pull requests

3 participants