#privacypass — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #privacypass, aggregated by home.social.
-
An overview of Privacy Pass - who uses it, how they use it, what it does, and how it does it. By @matthew_d_green https://blog.cryptographyengineering.com/2026/04/17/anonymous-credentials-an-illustrated-primer-part-2/
#PrivacyPass #AnonymousCredentials -
good overview of "Privacy Pass" - IETF zero-knowledge Authentification.
https://blog.kagi.com/kagi-privacy-pass
Privacy-Pass has been around for a while, but this is the first major webpage where I have encountered support.
-
good overview of "Privacy Pass" - IETF zero-knowledge Authentification.
https://blog.kagi.com/kagi-privacy-pass
Privacy-Pass has been around for a while, but this is the first major webpage where I have encountered support.
-
日刊IETF (2026-01-26)【PQC実装の本格化】JOSE/COSE対応とIoT環境への適用が加速
https://qiita.com/tetsuko_room/items/a23ff5effdeb41b714fc?utm_campaign=popular_items&utm_medium=feed&utm_source=popular_items -
【IETF124現地参加】プライバシー保護型トークン認証技術の最前線 【ゼロ知識証明 登場!?】
https://qiita.com/yumi-sakemi/items/bb8f617145e35249685d?utm_campaign=popular_items&utm_medium=feed&utm_source=popular_items -
We all know services that require authentication can correlate your activity on that service with your account. This becomes particularly dangerous when that account is linked with payment information that could potentially link back to your real identity.
It doesn't have to be this way though: The Privacy Pass protocol presents a path forward for "blind" authentication, if more services adopt it. Our team member @fria walks us through how it works:
https://www.privacyguides.org/articles/2025/04/21/privacy-pass/
-
We all know services that require authentication can correlate your activity on that service with your account. This becomes particularly dangerous when that account is linked with payment information that could potentially link back to your real identity.
It doesn't have to be this way though: The Privacy Pass protocol presents a path forward for "blind" authentication, if more services adopt it. Our team member @fria walks us through how it works:
https://www.privacyguides.org/articles/2025/04/21/privacy-pass/
-
Interesting #cryptography thing I stumbled upon: the #RFC for #PrivacyPass.
https://www.rfc-editor.org/rfc/rfc9576.html
"Privacy Pass is an architecture for authorization based on #privacy-preserving authentication mechanisms. In other words, relying parties authenticate Clients in a privacy-preserving way, i.e., without learning any unique, per-Client information through the authentication protocol, and then make authorization decisions on the basis of that authentication succeeding or failing. Possible authorization decisions might be to provide Clients with read access to a particular resource or write access to a particular resource." -
Interesting #cryptography thing I stumbled upon: the #RFC for #PrivacyPass.
https://www.rfc-editor.org/rfc/rfc9576.html
"Privacy Pass is an architecture for authorization based on #privacy-preserving authentication mechanisms. In other words, relying parties authenticate Clients in a privacy-preserving way, i.e., without learning any unique, per-Client information through the authentication protocol, and then make authorization decisions on the basis of that authentication succeeding or failing. Possible authorization decisions might be to provide Clients with read access to a particular resource or write access to a particular resource." -
so #apple uses #privacypass from #cloudflare for their own #webenvironmentintegrity: https://developer.apple.com/news/?id=huqjyh7k - but according to the register: https://www.theregister.com/2023/07/27/google_web_environment_integrity/
> #Google considers Apple Private Access Tokens to be too private.
wtf. apparently they want "some" #privacy, but not too much.
-
so #apple uses #privacypass from #cloudflare for their own #webenvironmentintegrity: https://developer.apple.com/news/?id=huqjyh7k - but according to the register: https://www.theregister.com/2023/07/27/google_web_environment_integrity/
> #Google considers Apple Private Access Tokens to be too private.
wtf. apparently they want "some" #privacy, but not too much.
-
I wonder, are these "Private Access Tokens" that #apple uses based on #cloudflare #privacypass? https://httptoolkit.com/blog/apple-private-access-tokens-attestation/ - going from not showing captchas to tor users to this is quite shocking.
-
CW: Long thread/49
Today, there's a cool remote attestation technology called "#PrivacyPass" that replaces #CAPTCHAs by having you prove to your own device that you are a human. When a server wants to make sure you're a person, it sends a random number to your device, which signs that number along with its promise that it is acting on behalf of a human being, and sends it back. CAPTCHAs are all kinds of bad - bad for accessibility and privacy - and this is really great.
49/
-
CW: Long thread/49
Today, there's a cool remote attestation technology called "#PrivacyPass" that replaces #CAPTCHAs by having you prove to your own device that you are a human. When a server wants to make sure you're a person, it sends a random number to your device, which signs that number along with its promise that it is acting on behalf of a human being, and sends it back. CAPTCHAs are all kinds of bad - bad for accessibility and privacy - and this is really great.
49/