Open OR13 opened 4 years ago
Agreed, not a good idea to have kid
here. JWEs already leak information about the receiver though the alg
and epk
. Let's not add more info leak.
I guess in some cases the recipient DID is already known. If this is the case then there should be no harm in adding a kid
in the JWE?
yes, i think there are cases where knowing the recipient is ok, particularly in the case of encrypted data vaults which MUST know the recipient to determine authorization to ciphertext.
Has not
kid
... which seems good from a privacy perspective.