martinthomson / dap-dp-ext

DAP extensions to support differentially-private submissions
Other
0 stars 0 forks source link

Tighten requester identity text #5

Open martinthomson opened 1 week ago

martinthomson commented 1 week ago

In our model for ad attribution, this field is critical because it ensures that reports for different requesters cannot be combined. An attacker that could combine reports under multiple different requesters, especially where they are have knowledge that shows that they come from the same person, can blow past sensitivity limits.

This also means that we have to ensure that tasks that use this extension only permit reports that include the fixed value for the extension.