ietf-wg-ppm / draft-ietf-ppm-dap-taskprov

Define DAP extension for in-band task provisioning.
Other
3 stars 4 forks source link

Privacy considerations: Tracking users across tasks #48

Closed cjpatton closed 4 months ago

cjpatton commented 1 year ago

@bemasc pointed out the following attack at IETF 118. A malicious Author can provision a Client with a unique task that allows it to track uploads from the Client over time. This might allow it to collude with the Leader and track where they are.

Is this an attack we're concerned about?

cjpatton commented 5 months ago

I think the only thing we can do here is not the attack in privacy considerations. Note that this is not an attack on the task binding property of the draft, but only the provisioning part.