Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make "false positive" detection opt-in / privacy-friendly #6

Open
mxstbr opened this issue Sep 10, 2021 · 0 comments
Open

Make "false positive" detection opt-in / privacy-friendly #6

mxstbr opened this issue Sep 10, 2021 · 0 comments

Comments

@mxstbr
Copy link
Contributor

mxstbr commented Sep 10, 2021

Some good ideas by @ThisIsMissEm: https://twitter.com/ThisIsMissEm/status/1435610947402539011

You could perhaps change it to be pull & compare, so comparison is done on the users' machine
Another option would be to use a comparison method like that which HIBP'd uses: hash the url, then send the first N bits of the hash to the server, returning any hashes & URLs that start with those bits; client then looks in that list to see if the URL was present

Should definitely incorporate some mechanism like this in the next release, at least an opt-in toggle would be good as a first MVP.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant