RE: draft regarding fingerprinting guidance

> >    $ Fingerprinting:   The process of an observer or attacker uniquely
> >       identifying (with a sufficiently high probability) a device or
> >       application instance based on multiple information elements
> >       communicated to the observer or attacker.  See [EFF].
> >
> > I wonder whether you find these definitions useful.

I agree with David that fingerprinting is in general reducing the space of possible identities and concentrating the belief about identity.

I'm a little concerned about "observer or attacker", since neither reasonably covers the main use case, which is that the origin server just uses data it was sent for other purposes. "observer" implies a passive observer separate from the main attacker. 

Received on Monday, 19 August 2013 22:43:18 UTC