Application Security and Permissions
How Meta enables de-identified authentication at scale

How Meta enables de-identified authentication at scale

3/30/2022 · Shiv Kushwah, Haozhi Xiong

What this post added

Introduced Anonymous Credential Service (ACS) as a new privacy-enhancing technology (PET) to enable de-identified authentication at source, moving from reactive data minimization to proactive de-identification. Detailed the protocol leveraging anonymous credentials, VOPRFs, and blind signatures, involving token issuance and de-identified authentication phases. Highlighted real-world use cases in WhatsApp telemetry and federated learning, and discussed the ACS architecture, scaling lessons learned (credential reuse limits, traffic dithering, global rate limiting), and self-service onboarding improvements.

Read the original post ↗