Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support immediate retraction of a health authority #34

Open
kenpugsley opened this issue Apr 1, 2020 · 3 comments
Open

Support immediate retraction of a health authority #34

kenpugsley opened this issue Apr 1, 2020 · 3 comments
Labels
enhancement New feature or request

Comments

@kenpugsley
Copy link

In the event that a health authorities site has been compromised, there needs to be a way to support an immediate revocation of the compromised data set from that authority.

Specific use case
The website of a health authority is compromised, and the data from that authority is modified to give erroneous results, perhaps adding in time-locations that will alarm the public. The authority would want a way to immediate retract that data while the site is brought back under control. It should be acceptable to retract all data for that authority, as long as that authority can be re-enabled when appropriate.

@kenpugsley kenpugsley added the enhancement New feature or request label Apr 1, 2020
@Ferrumofomega
Copy link

@kenpugsley Are you imagining this coming from the administrator of an HA? Or from a third-party revocation? Figuring out who has revocation rights for this open source but centralized .yml is going to be tricky.

The simplest version of this is just removing the HA URL from the YAML and adding a note that the HA has been compromised, no? Or are you picturing a flag to app users as well?

@kenpugsley
Copy link
Author

I think the simple approach of removing the HA from the list would work for the initial rollout. In reality I think there is some research / design that is required.

@AdamLeonSmith
Copy link
Contributor

One comment on this from a privacy perspective, in the EU the right to have personal data corrected is important. It would be useful if a HA could remove an individual record, which may also support this requirement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants