这是indexloc提供的服务,不要输入任何密码
Skip to content

Token Redemption: Limiting number of issuers configurable on a page #4

@csharrison

Description

@csharrison

At TPAC there was some concern about limiting publishers to a certain number of issuers (notes). This was a trade-off that we made between utility and privacy, because the more issuers there are on a page, the more bits of user-identity it is possible to leak in the worst case.

@tomlowenthal mentioned there might be an approach that can put a ceiling on the cross-site entropy by having some degree of negotiation between browsers and sites, and to allow browsers to pick which issuers to use (and do things intentionally inconsistently). Tom can you elaborate on what you were thinking here?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions