4 ms·
But the bank doesn't know where you're going. Only that you need to attest to verification. Further, if you encountered a bad KYC actor, there's this; which i
by jwally 1y ago
But the bank doesn't know where you're going.
Only that you need to attest to verification.
Further, if you encountered a bad KYC actor, there's this; which if I understand it makes it impossible to correlate you to a merchant by crypto alone.
https://arxiv.org/pdf/1907.06381 https://arxiv.org/pdf/1907.06381
You could use a VPN just for interacting with your bank or TOR for hyper vigilance...
p.s. thx sxp!
- perihelions 1y agoIf the bank and the website collude, they can de-anonymize attestation requests by correlating their two views of the interaction—the timestamps and various device fingerprints. It's impossible to make strong security guarantees against this threat model—imperfect statistical ones, at best. Your version makes this trivial, since per your other comment, you expect the bank to insist on seeing the same IP address as the website, as an anti-fraud measure. ("If your IP doesn't match what you had at the bank, the RP rejects you.")
- jwally 1y agoSalt and hash the IP or something so the RP can see the user's IP is the same as the bank's; but not necessarily _what_ the IP is...?
- perihelions 1y agoYou want the website to (1) look at a visitor's IP address, and (2) compare a cryptographic hash of that same IP address, to test for equality? Did you forget that (1) they have that IP address to begin with?
- jwally 1y agoGiven the static nature of most residential IP addresses, what stops this from happening today? If I subpoena facebook, google, chase, and pornhub - I can unmask who you are by correlating your IP and profile info. If I want higher certainty, I can further narrow down time windows.