ietf-wg-privacypass / draft-ietf-privacypass-rate-limit-tokens

Other
1 stars 5 forks source link

text about rate-limits being enforced by a single attester / issuer pair #9

Closed nikitaborisov closed 1 year ago

nikitaborisov commented 2 years ago

The PP arch document discusses the possibilities of an issuer potentially working with more than one attester. Likewise, an origin can work with multiple issuers. I think there should be some text that clarifies that in such cases, the rate limits enforced by a different attester and/or issuer would not apply to the user. Or, to put it a different way, the entity that is being rate-limited is defined by the attester working together with an issuer.

tfpauly commented 2 years ago

Correct, that's a good point. The Issuer chosen by the Origin must be selected in such a way that it will not allow working with Attesters that allow too much overlap — i.e., if you work with attesters based on hardware, it's fine, but don't mix email account and hardware attesters since you could have many of those.

chris-wood commented 1 year ago

We should also address the impact on centralization that this naturally forces.