3 ms·
This works by adding noise. Can't an attacker bypass it by boosting the signal? Assuming the attacker can create sybil advertisers/browsers, this should be tota
by stebalien 2y ago
This works by adding noise. Can't an attacker bypass it by boosting the signal? Assuming the attacker can create sybil advertisers/browsers, this should be totally doable:
1. Define some baseline set of M impressions with various ad identifiers and from various sybil advertisers.
2. For each target user, define some set of M marker impressions, also with various ad identifiers and from various and sybil advertisers.
3. Save all impressions (marker + baseline) on a bunch of sybil browsers to get above the reporting baseline with some probability.
4. If/when a target user visits a target website, request a conversion report for each ad/advertiser.
You now have a baseline signal (from the baseline ads/advertisers) and a marker signal (from the marker ads/advertisers). If this is one of your target users, you'd expect their "marker" signal signal to be stronger than the baseline.
- MrAlex94 2y agoTechnical docs are here: https://github.com/patcg-individual-drafts/ipa/blob/main/IPA-End-to-End.md https://github.com/patcg-individual-drafts/ipa/blob/main/IPA... Might be worth opening an issue if you believe there's merit to the attack?
- stebalien 2y agoI can try. But I'm pretty sure what they're trying to do is fundamentally impossible without some kind of sybil protection.
- stebalien 2y agoThose docs look out of date and appear to be designed for "app" ecosystems. The latest proposal from Mozilla is https://docs.google.com/document/d/1QMHkAQ4JiuJkNcyGjAkOikPKNXAzNbQKILqgvSNIAKw/edit#heading=h.5wiflfzeuvfm https://docs.google.com/document/d/1QMHkAQ4JiuJkNcyGjAkOikPK... And I'm now quite sure this system is insecure. Fundamentally, either: 1. There is some magical sybil protection: An attacker can only spend their own privacy budget without affecting the rest of the system. 2. The system can be saturated: An attacker can spend everyone's privacy budget. 3. The system is not private: An attacker can exceed the "safe" privacy budget by combining information from multiple sybils.
- MrAlex94 2y agoI assume it’s the MPC part that would need the Sybil protection? Also, another assumption, but it’s that doc still builds upon the W3C proposal - would it not be worth raising as an issue in the repo? Seems to still be active.
- stebalien 2y agoIt's all other parties, actually. I'm assuming Mozilla and friends are trusted and that the cryptography is perfect. I've filed an issue at https://github.com/patcg-individual-drafts/ipa/issues/90 https://github.com/patcg-individual-drafts/ipa/issues/90 but I'm still not sure if that's the right repo.