Skip to content

Security Horizontal Review #476

Description

@simoneonofri

Dear Group,

The following comments result from the Security Review and have been checked against the current Working Draft.

Reviewed version: Attribution Level 1, W3C Working Draft, 5 August 2026

Security review request: w3c/security-request#137

I have one editorial suggestion.

Aggregate-result trust assumptions are documented but not integrated in the Security Considerations section

Description: The relevant assumptions are already documented, but in different places:

  • 6.1 states that input confidentiality holds as long as either MPC operator is honest, while either operator can corrupt the output.
  • DAP-18 8 states that correct computation requires both Aggregators to execute the protocol honestly and distinguishes between valid and truthful measurements.
  • DAP-Attribution 4 states that, under Collector-selected batching, the Collector controls which reports are included.
  • 8.5.1 states that a conversion site can exclude reports it considers fraudulent.

8.3 focuses on disclosure risk and operator trust, but does not bring these assumptions together to explain what an attribution result does and does not assure.

Impact: It is possible to misunderstand the one-honest-MPC-operator confidentiality guarantee while missing that the result correctness depends on both Aggregators and that the set of reports included in an aggregate may be intentionally selected or filtered. This could lead to attribution results being assigned stronger assurances of integrity, completeness, or truthfulness than those provided.

Suggestion: Add a short summary in 8.3 to distinguish input confidentiality, aggregate-result integrity, measurement validity vs truthfulness, and report inclusion, referencing the sources of the summary.

Affected section:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-trackerGroup bringing to attention of security, or tracked by the security Group but not needing response.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions