- 0 Posts
- 7 Comments
JFC… What a surreal damned world. That’s ludicrous, but if you look at what Trump say or does is doesn’t even come close.
tomatolung@sopuli.xyzto
Technology@lemmy.world•Cloudflare, Chrome, Firefox Developing Next-Gen Privacy Pass: PACTsEnglish
18·3 months agoI asked Sonnet why should or shouldn’t trust a PACT, For what that is worth:
Reasons to Trust It
- The privacy is in the math, not in promises.
Unlike a privacy policy, which is a legal document you have to sue someone to enforce, cryptographic unlinkability is enforced by mathematics. If the blind signature scheme is correct, physically connecting your identity to your token redemption is computationally infeasible - not just forbidden by terms of service.
- Separation of knowledge is structural.
The design deliberately splits what each party knows so that no single organization - not even Cloudflare - can see the full picture. This is called the “need to know” principle enforced by protocol design rather than policy.
- It is open and being standardized.
This is going through the W3C and IETF - public standards bodies where cryptographers around the world can review, attack, and critique the design. Contrast this with Google’s Web Environment Integrity proposal, which was designed unilaterally and killed by public backlash.
- MPC prevents any single party from aggregating data.
When sites want to measure “how good are our Anchors?” they use Multiparty Computation (MPC) - a technique where multiple parties each hold a piece of encrypted data, compute a result together, and none of them ever sees anyone else’s raw data.
Reasons to Be Cautious
- Collusion is still theoretically possible.
The system’s privacy guarantees break down if the organizations involved secretly cooperate. The architecture tries to make this structurally unlikely (different companies with competing interests), but it cannot make it mathematically impossible.
- The Anchor becomes a new gatekeeper.
If most Anchors are big tech companies, and you don’t have accounts with them, you may find yourself unable to pass PACT checks - effectively locked out of parts of the web. This is exactly the criticism leveled at the old Apple PAT system.
- It is still in design phase.
The technical details of PACTs are still being finalized. 3 The devil is always in the implementation details.
It does seem worth looking into the setup of this, as I admit too a healthy amount of skepticism, but a bunch of people gave it some thought and some of the choices don’t look like money grubbing corporate ones.
tomatolung@sopuli.xyzto
Technology@lemmy.world•Apple Faces £3 Billion UK Trial Over iCloud Lock-In ClaimsEnglish
2·4 months agoTo your point it’s one of the levers regulators and governments have against corporate entities.
It’s a difficult venue, but it does work even if it seems like it has a minor effect. It creates disincentives and incentives which business are influenced by.
It would be better if regulators had more teeth, but capitalist defang whenever they can. Be it laws, regulators, or even just public influence.
tomatolung@sopuli.xyzto
Lemmy Shitpost@lemmy.world•We thought it would be free forever
31·5 months agoAh, yes the idiots they found.
tomatolung@sopuli.xyzto
Technology@lemmy.world•Push to repeal Section 230 raises stakes for how social media moderates contentEnglish
9·7 months agoWorth reading on the background of 230 https://www.internetsociety.org/blog/2026/02/30-years-of-section-230-why-we-still-need-it-for-a-safer-internet/
I mean this is a shipost…