Skip to content

Add global privacy budget and per-impression-site quotas #237

@martinthomson

Description

@martinthomson

We don't have a lot of text currently on privacy budget "safety limits", so we should rectify that.

The recent presentations we've had suggest two very simple protection measures:

  1. The global privacy budget, which might be the concrete thing we need to provide a privacy "guarantee".
  2. A quota for impression sites that we can use to ensure that one impression site can't exhaust the entire global budget.

There were other things in the work, but I think we can add just these for now.

We'll need to identify that each is some factor of the per-site budget, with some advice, but these are ultimately implementation-defined in a way that might need to be tweaked and tuned as we learn more. (For the quotas, @bmcase and I discussed maybe allowing some site-level heuristics that would help tighten things on the one hand, but expand to account for usage.)

Metadata

Metadata

Assignees

No one assigned

    Labels

    cr-blockerThis issue needs be resolved before we go to CR (snapshot).

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions