Summary
- W3C’s 24 September 2026 Working Draft of EPUB Annotations 1.0 replaces the previous draft’s empty security section with guidance on untrusted imported notes, forged creator claims and unsafe content. It is a revision of a Working Draft, not a Recommendation.
- The draft says a detached annotation set must be matched to a publication without any universally accepted EPUB publication identifier. Its
creatorfield can name someone without authenticating them. - A receiving reader therefore needs separate decisions on book matching, attribution, safe processing and ID collisions. This four-part handoff is an editorial reading of the draft, not a W3C-mandated checklist.
A reader exports years of highlights, then imports the file into a new reading system. The notes appear beside familiar passages, perhaps with the name of a teacher or colleague. That comfortable scene is a hypothetical workflow, not a reported security incident. It hides two different questions: did the notes land in the right publication, and did the named person actually make them?
The Publishing Maintenance Working Group’s 24 September draft makes this distinction harder to overlook. In the 20 September version, both the privacy and security sections simply said T.B.D.. The revised security section now describes external annotation sets as untrusted input, warns that a detached file’s Creator object can be forged, and asks reading systems to distinguish local notes from unverified imports. The privacy section remains unfinished. Neither revision establishes that a reader or vendor has implemented the guidance.
EPUB Annotations is designed as an interchange profile of the Web Annotation Data Model. An AnnotationSet can package notes for export and import, accompanied by about metadata intended to help identify the publication. The draft explicitly says there is no universally accepted identifier for EPUB publications. A title, creator and date in the set, or a selector pointing to a plausible chapter, can help a receiving system make a match. They cannot by themselves prove that a detached file belongs to this particular copy or edition. The draft accordingly expects an interface that can help the reader map a set and warn when checks suggest a mismatch.
Attribution is a second boundary, not a bonus conferred by successful book matching. The annotation’s creator metadata may identify a person, organization or software agent, but the new security section says detached sets carry no inherent authenticity guarantee. It advises treating a creator claim as unverified unless delivery used an authenticated channel or the set was cryptographically signed. The draft does not specify a signature format or a trust service; neither a name in JSON nor the sight of the right page is a signature.
Safe processing is a third decision. The draft forbids reading systems from interpreting markup embedded in a textual note as executable or rendered HTML. It also discusses external fetches that may reveal an IP address or trigger server-side requests, paths that might escape an EPUB container, and selectors crafted to consume excessive resources. Those are implementation hazards described by a draft, not a claim that any named product is vulnerable. A receiving system can display a note without granting every URL and selector an open-ended privilege.
Finally, an annotation ID collision is not an identity verdict. After publication context is checked, the draft expects a reader to update the existing note or ask the user rather than duplicate it. That leaves a governance choice at the point of import: what evidence justified the book match, whose authorship was actually checked, what content was constrained, and whether a conflicting local record was replaced? Keeping those decisions visible preserves portability without presenting it as proof.
The document remains a Working Draft, subject to change and not endorsed as a final W3C standard. Its new security chapter advances the public design conversation, while its privacy chapter is still a placeholder. The practical limit is clear even before a final specification: a portable note is data that can be carried, not authority that can be assumed.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

