Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Propose text for malicious issuers #57

Merged
merged 5 commits into from
Mar 6, 2023
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions index.html
Original file line number Diff line number Diff line change
Expand Up @@ -705,6 +705,25 @@ <h3>Content Distribution Networks</h3>
</p>
</section>

<section class="informative">
<h3>Malicious Issuers and Verifiers</h3>
<p>
In general, the herd privacy protections offered by this specification can be circumvented by malicious <a>issuers</a> and <a>verifiers</a>. Its privacy benefits can only be realized when issuers and verifiers intend to avoid tracking or sharing the presentation of particular credentials.
</p>
<p>
A malicious <a>issuer</a> might intentionally attack herd privacy by creating a
unique status list per credential issued in order to establish a 1-1 mapping to track
when a <a>verifier</a> processes a specific credential. Similarly, they could establish
another a 1-1 mapping by using a different cryptographic key for every credential
issued that is tracked in a status list.
</p>
<p>
A malicious <a>verifier</a> might intentionally attack herd privacy by sharing
information from presented credentials with a malicious <a>issuer</a>.
</p>
<p class="issue" data-number="6"></p>
OR13 marked this conversation as resolved.
Show resolved Hide resolved
</section>

</section>

<section class="informative">
Expand Down