Chromestatus
unread,4:41 PM (2 hours ago) 4:41 PMSign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to blin...@chromium.org, ayk...@google.com, eko...@google.com, kaust...@google.com, pth...@google.com, samschl...@google.com
Contact emails
ayk...@google.com,
kaust...@google.com,
samschl...@google.com,
pth...@google.com,
eko...@google.com
Explainer
https://github.com/explainers-by-googlers/private-verification-tokens
Specification
No information provided
Design docs
https://github.com/explainers-by-googlers/private-verification-tokens
Summary
Automated traffic is increasing across the web, and many websites have responded with more user friction in the form of CAPTCHAs and other challenges to combat unwanted traffic. This degrades the web user experience for all users, with a particularly outsized impact to users in private browsing modes.
Private Verification Tokens (PVT) is a low entropy mechanism that allows websites to transfer the trust that their users have established in regular browsing into private browsing mode to reduce their experienced user friction. PVTs are issued during a regular browsing session and redeemed in private browsing mode.
Blink component
Blink
Web Feature ID
Missing feature
TAG review
No information provided
TAG review status
Pending
Goals for experimentation
The experiment aims to verify whether positive reputation built up by a user on a particular website in regular browsing mode can be used to earn a lower friction experience on the same website when in private browsing mode. Over the course of the experiment, we expect participants to iterate on their methodology for token issuance, and validate the correlation of positive reputation carried into private browsing mode with existing signals indicating benign (i.e. non-abusive usage). The ultimate goal would be to reduce friction for users with positive reputation available, but for the experiment, we expect to validate the usefulness of the signal in aiding bot detection defenses.
Origin Trial documentation link
https://github.com/explainers-by-googlers/private-verification-tokens
Risks
Interoperability and Compatibility
No information provided
Gecko: No signal We have not yet officially requested a signal from Firefox yet, but we expect it to be negative based on conversations in standards groups like the W3C Anti-Fraud Community Group. We will formally request their review based on the outcome of the experiment. Bot detection is an ambiguous space, and there are multiple solutions and ideas that have been tried before, and some that are under active discussion in standards bodies. PVTs tackles a scoped version of the broader problem with simpler properties, and we think it's worth experimenting with to see how our design will perform in practice.
WebKit: No signal
Web developers: No signals
Other signals:
WebView application risks
Does this intent deprecate or change behavior of existing APIs,
such that it has potentially high risk for Android WebView-based
applications?
No
Ongoing technical constraints
None
Debuggability
None
Will this feature be supported on all six Blink platforms
(Windows, Mac, Linux, ChromeOS, Android, and Android WebView)?
No
No webview support.
No
Flag name on about://flags
kEnablePrivateVerificationTokens
Finch feature name
kEnablePrivateVerificationTokens
Requires code in //chrome?
True
Tracking bug
https://crbug.com/500396188
Launch bug
https://launch.corp.google.com/launch/4465636
Estimated milestones
| Origin trial desktop first | 154 |
| Origin trial desktop last | 165 |
| Origin trial Android first | 154 |
| Origin trial Android last | 165 |
Link to entry on the Chrome Platform Status
https://chromestatus.com/feature/6210457816924160?gate=6479261834805248
Links to previous Intent discussions
Intent to Prototype:
https://groups.google.com/a/chromium.org/d/msgid/blink-dev/69d805cc.050a0220.1c79a0.1052.GAE%40google.com