Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removing match key provider from HPKE for now #659

Merged
merged 2 commits into from
May 26, 2023

Conversation

richajaindce
Copy link
Contributor

@richajaindce richajaindce commented May 24, 2023

Based on patcg-individual-drafts/ipa#57, there is an attack that a malicious Match Key Provider (MKP) can carry out by creating fake sites and using those sites' privacy budgets to measure events that happened on its own source or trigger site. Until we are able to find a good mitigation to this attack, we have decided to move forward with no match key provider in the IPA design.
This PR removes mkp from being added to associated data in hpke.

@akoshelev
Copy link
Collaborator

Can you please add an explanation why we are doing it in the PR description, so things don't get lost in history?

@akoshelev akoshelev merged commit e38073c into private-attribution:main May 26, 2023
@richajaindce richajaindce deleted the hpke_cleanup branch July 21, 2023 04:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants