home.social

#privacypass — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #privacypass, aggregated by home.social.

fetched live
  1. good overview of "Privacy Pass" - IETF zero-knowledge Authentification.

    blog.kagi.com/kagi-privacy-pass

    Privacy-Pass has been around for a while, but this is the first major webpage where I have encountered support.

    #privacypass #kagi_search

  2. good overview of "Privacy Pass" - IETF zero-knowledge Authentification.

    blog.kagi.com/kagi-privacy-pass

    Privacy-Pass has been around for a while, but this is the first major webpage where I have encountered support.

    #privacypass #kagi_search

  3. We all know services that require authentication can correlate your activity on that service with your account. This becomes particularly dangerous when that account is linked with payment information that could potentially link back to your real identity.

    It doesn't have to be this way though: The Privacy Pass protocol presents a path forward for "blind" authentication, if more services adopt it. Our team member @fria walks us through how it works:

    privacyguides.org/articles/202

    #Privacy #PrivacyPass #Anonymity #PrivacyGuides #Article

  4. We all know services that require authentication can correlate your activity on that service with your account. This becomes particularly dangerous when that account is linked with payment information that could potentially link back to your real identity.

    It doesn't have to be this way though: The Privacy Pass protocol presents a path forward for "blind" authentication, if more services adopt it. Our team member @fria walks us through how it works:

    privacyguides.org/articles/202

    #Privacy #PrivacyPass #Anonymity #PrivacyGuides #Article

  5. Interesting #cryptography thing I stumbled upon: the #RFC for #PrivacyPass.
    rfc-editor.org/rfc/rfc9576.htm
    "Privacy Pass is an architecture for authorization based on #privacy-preserving authentication mechanisms. In other words, relying parties authenticate Clients in a privacy-preserving way, i.e., without learning any unique, per-Client information through the authentication protocol, and then make authorization decisions on the basis of that authentication succeeding or failing. Possible authorization decisions might be to provide Clients with read access to a particular resource or write access to a particular resource."

  6. Interesting #cryptography thing I stumbled upon: the #RFC for #PrivacyPass.
    rfc-editor.org/rfc/rfc9576.htm
    "Privacy Pass is an architecture for authorization based on #privacy-preserving authentication mechanisms. In other words, relying parties authenticate Clients in a privacy-preserving way, i.e., without learning any unique, per-Client information through the authentication protocol, and then make authorization decisions on the basis of that authentication succeeding or failing. Possible authorization decisions might be to provide Clients with read access to a particular resource or write access to a particular resource."

  7. I wonder, are these "Private Access Tokens" that #apple uses based on #cloudflare #privacypass? httptoolkit.com/blog/apple-pri - going from not showing captchas to tor users to this is quite shocking.

  8. CW: Long thread/49

    Today, there's a cool remote attestation technology called "#PrivacyPass" that replaces #CAPTCHAs by having you prove to your own device that you are a human. When a server wants to make sure you're a person, it sends a random number to your device, which signs that number along with its promise that it is acting on behalf of a human being, and sends it back. CAPTCHAs are all kinds of bad - bad for accessibility and privacy - and this is really great.

    49/

  9. CW: Long thread/49

    Today, there's a cool remote attestation technology called "#PrivacyPass" that replaces #CAPTCHAs by having you prove to your own device that you are a human. When a server wants to make sure you're a person, it sends a random number to your device, which signs that number along with its promise that it is acting on behalf of a human being, and sends it back. CAPTCHAs are all kinds of bad - bad for accessibility and privacy - and this is really great.

    49/