4 ms·
They give you a key and only if you have a higher tier account. The act of doing that requires that there is a step in the process where they know you’re reques
by t-writescode 9mo ago
They give you a key and only if you have a higher tier account. The act of doing that requires that there is a step in the process where they know you’re requesting a key and who you are. They could bind them in the backend if they wanted, before giving it to you.
You’re still trusting them. Not to mention they could round them all up by IP or browser fingerprinting.
There is still some level of trust.
I happen to trust them enough for that; but it is still trust.
- dooglius 9mo agoI am not an expert in the underlying cryptography, but the claim is indeed that the cryptographic approach makes it impossible for them to link the key to the queries in the backend.
- t-writescode 9mo agoSure! But there is a stage where they generate those keys for you and give them to you. You need to be logged in to get that page. That is trust there.
- hamdingers 9mo agoNo, issuer-client unlinkability is a feature of the design. The token is finalized by the client using private inputs so Kagi never actually sees the redeemable token (until it's redeemed). https://blog.kagi.com/kagi-privacy-pass#token-generation:~:text=The%20tokens%20eventually%20generated%20by%20the%20client%20at%20the%20end%20of%20this%20phase%20are%20indistinguishable%20from%20a%20randomly%20generated%20token%20from%20the%20server%E2%80%99s%20point%20of%20view.%20They%20cannot%20be%20traced%20back%20to%20the%20user%20who%20generated%20them%2C%20or%20to%20other%20tokens%20generated%20by%20the%20same%20user%20at%20the%20same%20or%20a%20different%20time https://blog.kagi.com/kagi-privacy-pass#token-generation:~:t.... https://www.rfc-editor.org/rfc/rfc9576.html https://www.rfc-editor.org/rfc/rfc9576.html
- t-writescode 9mo agoUsing the example doc you’re citing from kagi.com - though not the RFC, I don’t have the time to dive into that one at the second, I see that a session token plus some other stuff is passed in and a token comes out. Where does it show that on the Kagi backend they couldn’t, theoretically, save the session key before performing the token response?
- hamdingers 9mo agoSure, they probably do. Doesn't matter because neither the session key nor the token response can be linked to the tokens. If you're not going to make an effort to understand how it works, don't make assertions about how it works. Ask your favorite LLM about the RFC if you have any further questions.