4 ms·
I can't upvote this enough, there's money in that and whoever owns the infrastructure stands to make money off the data.
by nekoashide 4y ago
I can't upvote this enough, there's money in that and whoever owns the infrastructure stands to make money off the data.
- Dylan16807 4y ago"can't upvote this enough" because you think the cryptography is wrong, or because you didn't read the description?
- feet 4y agoOr because they think tracking is bad....?
- Dylan16807 4y agoThe cryptography says tracking a token is not possible. So would you like to elaborate on that point? I see you made a different comment about correlating connections but you can get a bunch of tokens at once and slowly go through the pile over several hours, as far as I know.
- feet 4y agoWhy would it not be possible? Is the code available for inspection?
- Dylan16807 4y agoBasically, the client picks some numbers, gets one derivative of those numbers signed, and presents a different derivative of its numbers to be verified. With the right math, there's no way to connect the two transactions. https://www.ietf.org/id/draft-ietf-privacypass-protocol-04.html https://www.ietf.org/id/draft-ietf-privacypass-protocol-04.h... https://privacypass.github.io/protocol/ https://privacypass.github.io/protocol/