|
|
|
|
|
by jsnell
1196 days ago
|
|
According to this: https://github.com/WICG/turtledove/blob/main/FLEDGE_k_anonym... You'll need to spend a Private State Token to call the k-anon API, minting PSTs is rate limited on the server side, and the client and server still cooperate to make forging PST requests hard (e.g. device integrity attestation, requiring the user be signed into Chrome). What I think this means is that you could undermine the k-anonymity in individual cases by large amounts of manual work, but not do so at scale. |
|
Beyond Private State Tokens we also have new cryptography we're researching that should let us improve unlinkability between issuance and redemption further.
https://github.com/WICG/turtledove/blob/main/FLEDGE_k_anonym...
https://eprint.iacr.org/2023/320