Anonymous Credentials Meeting 2020 Resources

Hello!

Thank you so much for having attended the Anonymous Credentials Meeting 2020 or for being interested by it!

This meeting was organized by Sofía Celi and Chris Wood.

The meeting was held in January along side with Real World Crypto 2021.

Here you can find some resources of it.

Slides

Additional resources

Tor case

Facebook case

Brave case

Notes from the meeting

Introduction by Sofía Celi

As we know, there is a Privacy Pass Working Group (WG) is an effort of IETF. But there are many use cases beyond it that we will like to tackle as well. Let’s hear about them, and take them back to the WG.

Ben Schwartz (IETF chair for Privacy Pass WG): Privacy Pass, current status

Tor users began seeing an increase in the number of CAPTCHAs. Cloudflare was concerned about rate limiting.

Chrome initiative with Trust Token (late 2019). Steven Valdez is leading this work. The W3C adopted this approach, and Chrome deployed this as part of its origin experiment. There are few variants that have been developed by academics.

Finally, a new WG was formed at IETF: drafts around the protocol itself, architecture and https.

We would like to know what is needed for them to be implemented, and help us solve some open questions: how to model client linkability, tradeoffs between metadata, anonymity set size, issuer consolidation pressure, and public key commitment approaches.

Eli-Shaoul Khedouri (hCaptcha): Overview of how it is used

In practice:

Security issues

Considerations

Steven Valdez (Google Chrome Privacy Sandbox): Trust tokens API

This is Privacy Pass as a Web API (a Chrome Web API).

Goals

Application

At Google

Standards

Comments from Michele Orru:

Google (and Cloudflare) would like to get rid of the actual issuance and leave it to third parties. This is critical and no company has enough trust in external providers to do it.

Subodh Iyengar (Facebook): PrivateStats

Privacy Pass style API in Whatsapp

Application

Architecture

Challenges

In practice

New construction: AB-VOPRF

George Kadianakis (Tor project) - Insight from Tor

Their interest started years ago. This was to unblock people to access nodes. There are DDoS against nodes and against the network itself.

They would like to:

They don’t have the resources to look at it, and information is not easy to get. The terms are not consistent across the literature.

Gonçalo Pestana and Iñigo Querejeta (Brave) - Brave Rewards use case

This is built on Privacy Pass. This is used for BAT redemption. The full model is on GitHub.

Goals

Two types of tokens

They would like

Martin Strand (Norway Covid app) - How we use Privacy Pass

The blog is available here

They would like:

Steps to take