Robust, privacy-preserving, transparent, and auditable on-device blocklisting

04/06/2023
by   Kurt Thomas, et al.
0

With the accelerated adoption of end-to-end encryption, there is an opportunity to re-architect security and anti-abuse primitives in a manner that preserves new privacy expectations. In this paper, we consider two novel protocols for on-device blocklisting that allow a client to determine whether an object (e.g., URL, document, image, etc.) is harmful based on threat information possessed by a so-called remote enforcer in a way that is both privacy-preserving and trustworthy. Our protocols leverage a unique combination of private set intersection to promote privacy, cryptographic hashes to ensure resilience to false positives, cryptographic signatures to improve transparency, and Merkle inclusion proofs to ensure consistency and auditability. We benchmark our protocols – one that is time-efficient, and the other space-efficient – to demonstrate their practical use for applications such as email, messaging, storage, and other applications. We also highlight remaining challenges, such as privacy and censorship tensions that exist with logging or reporting. We consider our work to be a critical first step towards enabling complex, multi-stakeholder discussions on how best to provide on-device protections.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/14/2023

Keep your Identity Small: Privacy-preserving Client-side Fingerprinting

Device fingerprinting is a widely used technique that allows a third par...
research
03/01/2021

Safepaths: Vaccine Diary Protocol and Decentralized Vaccine Coordination System using a Privacy Preserving User Centric Experience

In this early draft, we present an end-to-end decentralized protocol for...
research
06/14/2022

Private Set Matching Protocols

We introduce Private Set Matching (PSM) problems, in which a client aims...
research
10/09/2019

Privacy-preserving and yet Robust Collaborative Filtering Recommender as a Service

Collaborative filtering recommenders provide effective personalization s...
research
02/10/2020

WibsonTree: Efficiently Preserving Seller's Privacy in a Decentralized Data Marketplace

We present a cryptographic primitive called WibsonTree designed to prese...
research
09/03/2021

Increasing Adversarial Uncertainty to Scale Private Similarity Testing

Social media and other platforms rely on automated detection of abusive ...
research
11/04/2021

CryptoNite: Revealing the Pitfalls of End-to-End Private Inference at Scale

The privacy concerns of providing deep learning inference as a service h...

Please sign up or login with your details

Forgot password? Click here to reset