Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Abuse of the word "anonymous" #26

Open
bortzmeyer opened this issue Apr 19, 2020 · 5 comments
Open

Abuse of the word "anonymous" #26

bortzmeyer opened this issue Apr 19, 2020 · 5 comments
Labels
documentation Improvements or additions to documentation

Comments

@bortzmeyer
Copy link

It seems that the ROBERT document uses "anonymous" quite liberally. The worst is "anonymous
pseudonym" (an oxymoron) in the summary document. Anonymity requires the lack of traceability. If identifiers are permanent, they cannot be called "anonymous". This sloppy use of "anonymous" is common in the paper.

@ldubost
Copy link

ldubost commented Apr 19, 2020

There are indeed a few places where the pseudonyms don't seem to be impossible to trace:

1/ It is mentioned they are generated by the server which "knows" they are linked to your application. Since the application comes from an IP address, there is already a trace between the pseudonyms and an IP address and then a trace between each pseudonyms available to the authority

2/ At every "exposure status request" there is again the connection metadata that is available. There is also all the other pseudonyms which could be used to create a social graph and help for identifiying users.

So unless there is a mecanism to protect the connection metadata from the authority, there is already some important information linked to the pseudonyms.

Knowing that fixed IP addresses (many of the boxes at home or at work) are already reversable to geo-location by anybody and most of the IPs are reversable to the customer by the operators, it's not clear how the anonymity is a given here

@ThomasFournaise
Copy link

As long as IDs are generated centrally, anonymous cannot be used.
For security purpose you must store IPs that send request.
By exporting the table and the logs you can then cross the information and get a link IP / IDs even if this link is not stored in the database.
The whole protection is said here 'Authority is honest but curious" so you must trust government and what could go wrong....

@kaythxbye
Copy link

kaythxbye commented Apr 19, 2020 via email

@bortzmeyer
Copy link
Author

So unless there is a mecanism to protect the connection metadata from the authority, there is already some important information linked to the pseudonyms.

I'm afraid you are talking about something different. I mentioned the fact that ROBERT is not anonymous. You speak about the fact that pseudonyms can be linked to external identities, which is an important problem but not the same.

@bortzmeyer
Copy link
Author

Honest but curious is not even enough, it should be changed to trusted.

See ticket #13

@aboutet aboutet added the documentation Improvements or additions to documentation label Apr 19, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

5 participants