Skip to content

Conversation

@sakimura
Copy link
Member

No description provided.

Clarified the definition of the ephemeral subject identifier to emphasize non-reusability and the need for sufficient entropy in response values.
Clarify the definition of ephemeral identifier and add requirements for its usage.
To make it not possible for Clients to correlate the End-User's multiple visits, an OP

1. MUST NOT reuse an ephemeral identifier value;
2. MUST generate the value with a guessing probability of 2^128^ or less; and

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
2. MUST generate the value with a guessing probability of 2^128^ or less; and
2. MUST generate the value with a guessing probability of 2^-128^ or less; and


1. MUST NOT reuse an ephemeral identifier value;
2. MUST generate the value with a guessing probability of 2^128^ or less; and
3. SHOULD target 2^160^ or less.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
3. SHOULD target 2^160^ or less.
3. SHOULD target 2^-160^ or less.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants