← Back to context

Comment by StavrosK

7 years ago

The tokens can't be correlated with a user.

From the linked page "Privacy Pass uses elliptic curve cryptography to generate 'anonymous' tokens after a single CAPTCHA page is solved."

In any case - privacy implications aside - having to install an extension to get around their risk assessment algorithm going wrong seems like placing the burden in very much the wrong place.

edit: was wrong about who created the extension

  • PrivacyPass is not their thing:

    https://privacypass.github.io/

    They run a service that shows high-risk visitors (or whom they deem high-risk) a challenge. They support a third-party extension that lets you vouch for yourself on other websites anonymously. The alternative is that they don't support it.

    The other things they do are debatable, but this is a good thing.