Dear Group,
The following comments result from the Security Review and have been checked against the current Working Draft.
Reviewed version: Attribution Level 1, W3C Working Draft, 5 August 2026
Security review request: w3c/security-request#137
I have one editorial suggestion.
Aggregate-result trust assumptions are documented but not integrated in the Security Considerations section
Description: The relevant assumptions are already documented, but in different places:
- 6.1 states that input confidentiality holds as long as either MPC operator is honest, while either operator can corrupt the output.
- DAP-18 8 states that correct computation requires both Aggregators to execute the protocol honestly and distinguishes between valid and truthful measurements.
- DAP-Attribution 4 states that, under Collector-selected batching, the Collector controls which reports are included.
- 8.5.1 states that a conversion site can exclude reports it considers fraudulent.
8.3 focuses on disclosure risk and operator trust, but does not bring these assumptions together to explain what an attribution result does and does not assure.
Impact: It is possible to misunderstand the one-honest-MPC-operator confidentiality guarantee while missing that the result correctness depends on both Aggregators and that the set of reports included in an aggregate may be intentionally selected or filtered. This could lead to attribution results being assigned stronger assurances of integrity, completeness, or truthfulness than those provided.
Suggestion: Add a short summary in 8.3 to distinguish input confidentiality, aggregate-result integrity, measurement validity vs truthfulness, and report inclusion, referencing the sources of the summary.
Affected section:
Dear Group,
The following comments result from the Security Review and have been checked against the current Working Draft.
Reviewed version: Attribution Level 1, W3C Working Draft, 5 August 2026
Security review request: w3c/security-request#137
I have one editorial suggestion.
Aggregate-result trust assumptions are documented but not integrated in the Security Considerations section
Description: The relevant assumptions are already documented, but in different places:
8.3 focuses on disclosure risk and operator trust, but does not bring these assumptions together to explain what an attribution result does and does not assure.
Impact: It is possible to misunderstand the one-honest-MPC-operator confidentiality guarantee while missing that the result correctness depends on both Aggregators and that the set of reports included in an aggregate may be intentionally selected or filtered. This could lead to attribution results being assigned stronger assurances of integrity, completeness, or truthfulness than those provided.
Suggestion: Add a short summary in 8.3 to distinguish input confidentiality, aggregate-result integrity, measurement validity vs truthfulness, and report inclusion, referencing the sources of the summary.
Affected section: