Contact emails [email protected], [email protected], [email protected], [email protected], [email protected]
Explainer https://github.com/explainers-by-googlers/private-verification-tokens Specification No information provided Design docs https://github.com/explainers-by-googlers/private-verification-tokens Summary Automated traffic is increasing across the web, and many websites have responded with more user friction in the form of CAPTCHAs and other challenges to combat unwanted traffic. This degrades the web user experience for all users, with a particularly outsized impact to users in private browsing modes. Private Verification Tokens (PVT) is a low entropy mechanism that allows websites to transfer the trust that their users have established in regular browsing into private browsing mode to reduce their experienced user friction. PVTs are issued during a regular browsing session and redeemed in private browsing mode. Blink component Blink Web Feature ID Missing feature TAG review No information provided TAG review status Pending Goals for experimentation The experiment aims to verify whether positive reputation built up by a user on a particular website in regular browsing mode can be used to earn a lower friction experience on the same website when in private browsing mode. Over the course of the experiment, we expect participants to iterate on their methodology for token issuance, and validate the correlation of positive reputation carried into private browsing mode with existing signals indicating benign (ie non-abusive usage). The ultimate goal would be to reduce friction for users with positive reputation available, but for the experiment, we expect to validate the usefulness of the signal in aiding bot detection defenses. Origin Trial documentation link https://github.com/explainers-by-googlers/private-verification-tokens Risks Interoperability and Compatibility No information provided Gecko: No signal We have not yet officially requested a signal from Firefox yet, but we expect it to be negative based on conversations in standards groups like the W3C Anti-Fraud Community Group. We will formally request their review based on the outcome of the experiment. Bot detection is an ambiguous space, and there are multiple solutions and ideas that have been tried before, and some that are under active discussion in standards bodies. PVTs tackles a scoped version of the broader problem with simpler properties, and we think it's worth experimenting with to see how our design will perform in practice. WebKit: No signal Web developers: No signals Other signals: WebView application risks Does this intent deprecate or change behavior of existing APIs, such that it has potentially high risk for Android WebView-based applications? No Ongoing technical constraints None Debuggability None Will this feature be supported on all six Blink platforms (Windows, Mac, Linux, ChromeOS, Android, and Android WebView)? No No webview support. Is this feature fully tested by web-platform-tests? No Flag name on about://flags kEnablePrivateVerificationTokens Finch feature name kEnablePrivateVerificationTokens Requires code in //chrome? True Tracking bug https://crbug.com/500396188 Launch bug https://launch.corp.google.com/launch/4465636 Estimated milestones Origin trial desktop first 154 Origin trial desktop last 165 Origin trial Android first 154 Origin trial Android last 165 Link to entry on the Chrome Platform Status https://chromestatus.com/feature/6210457816924160?gate=6479261834805248 Links to previous Intent discussions Intent to Prototype: https://groups.google.com/a/chromium.org/d/msgid/blink-dev/69d805cc.050a0220.1c79a0.1052.GAE%40google.com This intent message was generated by Chrome Platform Status. -- You received this message because you are subscribed to the Google Groups "blink-dev" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/chromium.org/d/msgid/blink-dev/6a7f7d73.57cdfc94.1bf3cb.00bc.GAE%40google.com.
