Skip to content

Commit f3f0903

Browse files
authored
Merge pull request #56 from intarchboard/mirjak-patch-7
collusion through third parties
2 parents 3768269 + 04a466a commit f3f0903

File tree

1 file changed

+7
-3
lines changed

1 file changed

+7
-3
lines changed

draft-iab-privacy-partitioning.md

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -625,11 +625,15 @@ If the Oblivious Relay and Gateway collude, they can link Client identity and da
625625
for each request and response transaction by simply observing requests in transit.
626626

627627
It is not currently possible to guarantee with technical protocol measures that two
628-
entities are not colluding. However, there are some mitigations that can be applied
628+
entities are not colluding. Even if two entities do not collude directly, if both entities reveal
629+
information to other parties, it will not be possible to guarantee that the information won't
630+
be combined. However, there are some mitigations that can be applied
629631
to reduce the risk of collusion happening in practice:
630632

631-
- Policy and contractual agreements between entities involved in partitioning, to disallow
632-
logging or sharing of data, or to require auditing.
633+
- Policy and contractual agreements between entities involved in partitioning to disallow
634+
logging or sharing of data, along with auditing to validate that the policies are being followed.
635+
For cases where logging is required (such as for service operation), such logged data should
636+
be minimized and anonymized to prevent it from being useful for collusion.
633637
- Protocol requirements to make collusion or data sharing more difficult.
634638
- Adding more partitions and contexts, to make it increasingly difficult to collude with
635639
enough parties to recover identities.

0 commit comments

Comments
 (0)