New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 825205 link

Starred by 3 users

Issue metadata

Status: Available
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Feature



Sign in to add a comment

Let users delete their profiles when DeviceShowUserNamesOnSignin is disabled

Project Member Reported by tnagel@chromium.org, Mar 23 2018

Issue description

There's some policies that can make it impossible for a user to delete their account (DeviceShowUserNamesOnSignin, MinimumRequiredChromeVersion, DeviceUserWhitelist). We should come up with ways in which users can retain the ability to delete their account.

Context: https://groups.google.com/a/google.com/d/topic/chromeos-privacy/1Cbn414-SBY/discussion

> there will be many ways for admin restrictions to prevent the deletion of user data (put the device in lost-and-stolen mode, hide the pods as you suggest, put the device in auto-start-public-session mode, etc).

If a device is marked as lost-or-stolen there's probably a reason for it and blocking deletion in that case seems reasonable. I'm mostly concerned about the admin (unintentionally) blocking deletion as a side-effect of another action (e.g. hiding user pods).

> Is the option for the user to do a stateful clear sufficient as a fallback, so we don't have to go through all of these features now and in the future to build some kind of "delete my data" escape hatch?

I wouldn't consider wiping the device a reasonable alternative because this clears the state of *all* users on the device. I'd expect that the collateral damage could be a significant deterrent to that.

I don't think that we need to go through all existing features individually, it's probably sufficient to treat two cases:
a) the pod of a specific user is hidden from the login screen
b) the login screen itself is hidden

Let's get together after Easter and brainstorm potential solutions. Cc'ing Christian since he might be interested in integrating account deletion into Clear Browsing Data.
 
So agreed that deleting user data is nice to have here, but exposing this seems primarily like a UX issue - do we have any UX resources who can contribute here?

Comment 2 by tnagel@chromium.org, Mar 27 2018

We might take that occasion to discuss whether the model of any user can delete any user is still valid in an ARC++ world where significant state may be accumulated in users profiles.

Comment 3 by tnagel@chromium.org, Mar 27 2018

Whoops, collided with Drew's comment. I agree that we should get UX and PM input on this, especially if we decide to widen the scope to revamping user deletion in general.
Labels: Enterprise-Triaged
Status: Available (was: Untriaged)
Labels: -Pri-1 -Type-Bug Pri-2 Type-Feature
Owner: marcuskoehler@chromium.org
Marcus can you prioritize this privacy-related feature?
Cc: zalcorn@chromium.org
Labels: Hotlist-Privacy-Followup
+zalcorn who has been thinking about this as well.
Took a stab at this a go/cros-byebye
Cc: jessejames@google.com
 Issue 919809  has been merged into this issue.
One additional way we could approach the problem is to have users' accounts and associated data automatically remove themselves after being hidden from the login screen for (n~=30) days.  This would have the additional benefit of removing users data when they no longer have physical access to the device.

Comment 11 by glevin@google.com, Yesterday (45 hours ago)

Cc: tnagel@chromium.org glevin@chromium.org
jessejames@ - Following up on a question from  Issue 919809 :
"Do you have a way of tracking post-mauve follow up work?"
Is there a bug label that we can apply to indicate this?

Sign in to add a comment