generated from privacycg/template
-
Notifications
You must be signed in to change notification settings - Fork 16
Open
Labels
cr-blockerThis issue needs be resolved before we go to CR (snapshot).This issue needs be resolved before we go to CR (snapshot).
Description
We don't have a lot of text currently on privacy budget "safety limits", so we should rectify that.
The recent presentations we've had suggest two very simple protection measures:
- The global privacy budget, which might be the concrete thing we need to provide a privacy "guarantee".
- A quota for impression sites that we can use to ensure that one impression site can't exhaust the entire global budget.
There were other things in the work, but I think we can add just these for now.
We'll need to identify that each is some factor of the per-site budget, with some advice, but these are ultimately implementation-defined in a way that might need to be tweaked and tuned as we learn more. (For the quotas, @bmcase and I discussed maybe allowing some site-level heuristics that would help tighten things on the one hand, but expand to account for usage.)
Metadata
Metadata
Assignees
Labels
cr-blockerThis issue needs be resolved before we go to CR (snapshot).This issue needs be resolved before we go to CR (snapshot).