Devographics / Devographics/Monorepo

Handling privacy issues regarding cross-referencing

Open
#330 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
178
Forks
55
Avg merge
1m
Merged PRs (30d)
2

Description

### Problem

You know Alice lives in Madagascar and has taken the survey. You want to figure out their salary.

Since Alice is the only respondent from Madagascar, you can easily find out the salary by either filtering the salary chart to `country = madagascar`, or cross-referencing country vs salary.

### Solution

We implement a dataset cutoff so that any result with less than `n` (by default, `n=10`) will be zeroed out and accompanied with an "insufficient data" message.

### Conditions

We apply this cutoff when:

- a filter is active
- apply cutoff to all top-level (parent) buckets
- a facet is active
- apply cutoff to all second-level (facet) buckets

Note that if a filter is *not* active, we don't need to apply the cutoff to parent-level buckets even if a facet is active for properties such as `count`, `percentageSurvey`, etc. but we *do* need to zero out `averageByFacet` and `percentilesByFacet` since they can leak cross-referenced facet data.

### Exceptions

We *do not* apply the cutoff for "raw" results with no filters or facets applied. In other words, it's ok to show that Madagascar only has 1 respondent as long as that info is not filtered or cross-referenced with any other.

### Gotchas

We need to make sure there is no way to distinguish between empty brackets and zeroed out brackets. For example, it's not enough to replace the Madagascar bucket with an "insufficient data" bucket, we also need to create fake "insufficient data" buckets for the countries *that are not present at all in the dataset*. Otherwise it becomes possible to identify the real country by elimination.

### Limitations

At the moment, if a query does not return *any* data at all it will return an empty array, instead of zeroed out buckets.

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are named. Start by tracing how filters, facets, and raw results produce chart buckets, then map the cutoff and indistinguishable empty-bucket requirements to those paths. Done means filtered and cross-referenced results enforce the default n=10 cutoff without leaking the respondent, while raw results remain exempt.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
analytics, data, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.