-
Log3overLog2 So I def sped over this point, but the question you asked here is about "first parties have a way to delegate access to a user identity to specific 3p" which I read as a need for some PII may need to be sent to third parties...
-
Log3overLog2 And then I wanted to credit your note that depending on how third parties are allowed to process this, there is "the risk to the central threat of joining across per-site identities"...
-
Log3overLog2 My concern here is that it would seem to be very difficult if not impossible to prevent 3ps from respecting any standard, even if "sharded by 3p as well" there is still an opportunity for bad actors to connect the dots on identity in the back-end.