Discussion about this post

User's avatar
Marius Laurusevicius's avatar

The detail that stands out is that the encrypted block is handed to the client rather than kept server-side. That turns a provider secrecy question into a data retention question for whoever is storing those session logs. Does the paper say anything about how long clients typically hold those blocks before expiry?

The Pareto Investor's avatar

Stealing a model’s private thoughts is the security paper title of the year.

4 more comments...

No posts

Ready for more?