Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add link about security #906

Open
mgifford opened this issue Dec 8, 2021 · 5 comments
Open

Add link about security #906

mgifford opened this issue Dec 8, 2021 · 5 comments

Comments

@mgifford
Copy link

mgifford commented Dec 8, 2021

I figured this might encourage more people to question whether overlays are a good idea or not:

https://www.govloop.com/community/blog/government-websites-cant-rely-on-the-claims-of-accessibility-overlays/

It's not like you're adding Google Analytics to your site. There are many more risks involved.

@DagA11y
Copy link
Contributor

DagA11y commented Jan 26, 2022

As @mgifford wrote - all external scripts are a potential attack vector and security risk. For customers coming from EU it can also be worth mentioning that newest changes may make sending personal data out of EU illegal.

I am not a lawyer! But here is the latest info from NGO that caused the "wheels to move";

https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-analytics-illegal

In terms of overlays I imagine sites will potentially send very sensitive information about end users (for example disability info, together with IP addresses and maybe even personal identifier data from forms (third party scripts can have access if they choose so.

It would be an interesting security homework to check data being sent to overlay providers.

@mgifford
Copy link
Author

I would think that there would have to be implications for the GDPR. Also worth while noting that the GDPR is actually more global than most people think. It is worded in a way to protect European Citizens, not just the boundaries of continental Europe.

@DagA11y
Copy link
Contributor

DagA11y commented Jan 26, 2022

@mgifford - yes, for sure, the so called Schrems II is GDPR related. Agreed. And yes, GDPR is way more global than just EU.

@karlgroves
Copy link
Owner

Can someone write this up?

@karlgroves
Copy link
Owner

@DagA11y or @mgifford can one of ya'll add this link to the list of resources at the bottom?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants