About 22 minutes of class time; Predict is pre-class reading and Explain is a spoken debrief
Checked against
Lab commit 93f3f7226fe7 on 2026-09-22
NameDate
Predict
Answer these before you open the exhibit. There are no penalties for wrong predictions; the point is to compare them with what you see. No mathematics is needed for any of them.
A patron searches an ordinary library catalog for one title. For each of these four facts, say whether the operator of that catalog ends up holding it: the title requested, who asked, when they asked, how often that patron asks.
Now the same lookup is handled by two services run by two different organisations. Each service is sent a list of catalog positions, combines the records sitting at those positions into a single reply, and sends that reply back; the patron's own device puts the two replies together to get the book. Predict what one of those services, reading only the list it received, could say about which book the patron wanted.
Predict what those two organisations could work out about that patron if they laid the two lists they received side by side. Which of the four facts in question 1 would they hold between them?
Name one fact about a patron's catalog use that an arrangement like this cannot hide, and say why a librarian might still care about it.
Do
Open the exhibit. Before choosing anything, scroll to Naive vs. Private Query. The Naive query view is the one showing. Record its request line, exactly as it reads now, in the first row of the first table.
Scroll up to Library Catalog. Four of the eight books are shown, and Showing 4 of 8 — show all opens the rest. Click one of the four cards already showing — these steps use The Midnight Library — and read the line that appears under the catalog. Record the title and the index it names in the fourth table.
Go back to Naive vs. Private Query and record the Naive query request line again. Then press PIR query and record the line that view shows, before any query has run.
Scroll to Protocol Visualizer and read the note headed Teaching simulation at the top of that section. You will need it for Explain 5.
Back in Library Catalog, press Query Privately. Four steps run in a few seconds. When the last one finishes, scroll back up to the panel headed Client generates query pair and look at the two grids of eight squares, one under Server 1 receives and one under Server 2 receives: each square stands for one catalog slot, and each server was sent its own grid.
Scroll down to What each server knew and record, in the second and third tables: the slots listed under Server 1 saw: and the count beneath them, the same two values for Server 2 saw:, the title under Retrieved title:, and the line that appears under that title.
Press Run again and record those same six values for a second run of the same book.
Press Simulate the servers colluding, near the end of the privacy analysis. Record in the fourth table the position the page names, the book it names, and how that button reads once you have pressed it.
Return to Naive vs. Private Query, press PIR query, and record that line as it reads now. Put it beside the Naive query line you recorded in step 3.
Record
Every value below comes from your own run.
Moment
The request line, exactly as the page shows it
Naive query, before a book is chosen
blank for your answer
Naive query, after you chose your book
blank for your answer
PIR query, before any query has run
blank for your answer
PIR query, after your second run
blank for your answer
Run
Server 1 saw (slots)
Count under Server 1
Server 2 saw (slots)
Count under Server 2
First, after Query Privately
blank for your answer
blank for your answer
blank for your answer
blank for your answer
Second, after Run again
blank for your answer
blank for your answer
blank for your answer
blank for your answer
Run
Retrieved title
The line under the retrieved title
First
blank for your answer
blank for your answer
Second
blank for your answer
blank for your answer
What the page showed
Value
The book you chose, and the index in the line under the catalog
blank for your answer
The position named after the servers colluded
blank for your answer
The book named after the servers colluded
blank for your answer
How the collusion button reads after you pressed it
blank for your answer
Explain
Put two of your recorded request lines side by side: the Naive query line after you chose a book, and the PIR query line after your second run. For each, say what the operator receiving it could write in its log about the title requested, and what a librarian could honestly tell a patron about what that operator holds.
Compare Server 1 saw: with Server 2 saw: in your first run, then compare your first run with your second. Did the same book produce the same lists twice? The note beneath the two grids calls each square a bit, and says that neither server "can determine which bit differs — or which book you want. Only a party holding both can see it." Using your own recorded lists, say what that sentence means for a log kept by one operator over a term of student searches.
In your run, neither list on its own named your book, and the page named it exactly once the two were put together. Using what appeared after you pressed the collusion button, explain in your own words what "the servers must not collude" is asking of two organisations, and say which of your recorded values one operator would have had to obtain from the other to do this alone.
Find the paragraph in the privacy analysis that begins "Scoped precisely". List the facts it says this design does not hide. For each one, name the party in a real library deployment who would be in a position to learn it, and say which of your Predict 1 answers it matches.
The note headed Teaching simulation says what this page actually is, and what a real deployment would need instead. Using that note and the paragraph beginning "The two masks are not independent", name the assumption the page's privacy claim rests on and every party who has to be trusted for it to hold. Then say what, if anything, a patron at a catalog terminal could check for themselves.
Fix / Extend
Fix. A vendor tells your library that its catalog search is private because "neither of our two servers can tell which book a patron looked up". Using the paragraph beginning "The two masks are not independent" and the note headed Teaching simulation, write two questions you would put to that vendor before the library repeats the claim to patrons. For each question, name the recorded value or the page sentence that prompted it.
Fix. A library plans to run both servers itself, on one set of machines, under one administrator's account. The page says the threat model requires the servers to be operated by "independent, non-colluding parties". Say what that plan gives up, which of your recorded values demonstrates it, and how you would word the residual risk in a privacy impact assessment.
Extend. Press Query a different book, choose a card for a different title, press Query Privately, then press Simulate the servers colluding again. Did the page name the new book? Compare the two Server 1 saw: lists from your two different books and say what an operator holding both lists, and nothing else, could conclude about the two requests.
Extend. Scroll to How PIR scales — the √N trick and move the Catalog size slider to two of its positions, recording 1-D query (this demo) and √N matrix query at each. The note under those figures says they count "query bits only". Say what it tells you still has to travel back from each server, and why a library with a large catalog would want to know that before costing such a service.
About 23 minutes of class time; Predict is pre-class reading and Explain is a spoken debrief
Checked against
Lab commit 9de776c3565d on 2026-09-22
NameDate
Predict
Answer these before class, before you open the exhibit. This section is reading and writing you do away from the lab; the lab time on this sheet starts at Do. There are no penalties for wrong predictions; the point is to compare them with what you see. No mathematics is needed for any question on this sheet.
A patron searches through a service run by two operators: a relay, which receives the request from the patron's computer and passes it on, and a gateway, which opens the request and asks the catalog. For each operator, predict which of these it learns — the patron's network address, the words of the search, both, or neither. Write one line for the relay and one for the gateway.
Each operator keeps the ordinary records its job produces: the relay a list of addresses and arrival times, the gateway a list of searches and arrival times. Predict what the two could work out together that neither could work out alone, and whether they would have to break any encryption to do it.
Four patrons search at almost the same moment through that same pair of operators. Nobody decrypts anything, and the two operators never speak to each other — someone simply obtains both sets of records later. Predict whether that person could tell which patron sent which search, and name what in the records they would use.
A vendor tells your library: "patron searches are encrypted end to end, so we cannot see who searched for what." Predict what has to be true — about organizations, not about mathematics — for that sentence to hold, and say whether a patron's own computer could check it.
Do
In the panel The knowledge split, live, the box labelled Your sensitive input (query, or note body for POST) already holds a query. Replace it with a query you invent for this exercise. Do not type a real search of your own, a real name, or anything else about yourself: the panel asks you to make one up, and whatever you type is displayed in full further down the page and printed again in the collusion step below. Leave the two menus beside the box as they are, and press Run the exchange.
Press Jump to end, which fills every card at once. (Walking the exchange one step at a time, with the status line under those buttons, is an Extend item in the last section; you do not need it to fill the tables below.) Then read the four party cards — Client, Relay, Gateway, Target — and fill in the first Record table in the page's own words. Copy the Client card's "cannot know" line and the reason under it exactly; you will need it twice — in Explain question 3, and again in Fix / Extend. Finally, copy the value the Relay card shows beside timing + sizes into the second table.
Go to the panel The collusion toggle and read the paragraph under the heading before you touch anything. Record what the Cryptographic result box and the Privacy verdict box say now. Press Relay and gateway compare notes, and record both boxes again, plus the three lines of the joined log (WHO, WHAT, JOINED ON). Press the same control a second time to switch it back, and record both boxes once more.
Go to the panel Correlation without collusion. Leave Pad every request to 256 bytes (RFC 9292 §3.8) unticked and press Simulate 4 clients at once. Read the two logs side by side before you join anything — one is headed "Relay's access log (knows WHO)", the other "Gateway's log (knows WHAT, sorted by size)" — and note from those headings which of the two facts each log holds and which it lacks. Press Join the logs on size and record the result; then press Join the logs on timing and record that too.
Now tick Pad every request to 256 bytes (RFC 9292 §3.8). The page clears the result and asks for a fresh run, so press Simulate 4 clients at once again, then Join the logs on size and Join the logs on timing once more, recording both. Finish this panel by opening What padding does and does not fix and reading it.
Record
Every value below comes from your own run. Write phrases from the page rather than summaries, so you can quote them in the Explain section and in Fix / Extend.
Party card
A fact listed after "knows"
A fact listed after "cannot know", and the reason the page gives
Client
blank for your answer
blank for your answer
Relay
blank for your answer
blank for your answer
Gateway
blank for your answer
blank for your answer
Target
blank for your answer
blank for your answer
From the Relay card
What it reads
The value beside timing + sizes
blank for your answer
The collusion toggle
Cryptographic result, in the page's words
Privacy verdict, in the page's words
Before you press it
blank for your answer
blank for your answer
After one press
blank for your answer
blank for your answer
After a second press
blank for your answer
blank for your answer
Joined log line
What it read
WHO
blank for your answer
WHAT
blank for your answer
JOINED ON
blank for your answer
Padding
Join
Privacy verdict, in the page's words
How many of the clients the verdict names
Unticked
on size
blank for your answer
blank for your answer
Unticked
on timing
blank for your answer
blank for your answer
Ticked
on size
blank for your answer
blank for your answer
Ticked
on timing
blank for your answer
blank for your answer
Explain
Using your first table, name the party in this run that held the patron's address, the party that held the words of the search, and any party that held neither. Then finish this sentence for a colleague who will not see the exhibit: while the two operators stay apart, what the patron is relying on is not encryption but ____.
When you pressed the toggle, the Cryptographic result box and the Privacy verdict box said opposite-sounding things at the same time. Explain how both can be true together, and use the JOINED ON line you recorded to say what the two operators actually combined — and whether anything had to be decrypted for it.
The Client card names one thing the client cannot know, with a reason. Quote the reason, then say what a patron, or a library acting for its patrons, would have to do instead of checking that thing on the patron's own computer. Name one item a library could actually ask a vendor for.
Fix / Extend
Fix. A vendor brochure says patron searches are protected because they are encrypted in transit and the vendor's own servers never see a patron's address. Using your record tables and the row headed "What you must assume" in the panel Where this sits: OHTTP vs VPN vs Tor vs IT-PIR, name the assumption that claim actually rests on and the party who has to keep it. Then write one question the library should ask before signing. Claim no more than the exhibit showed you.
Fix. Suppose your library keeps a web-proxy log and a discovery vendor keeps a search log, and neither is shared with the other today. Using your correlation rows, say what could be recovered if one party later obtained both sets, and propose one change to what is logged, how long it is kept, or who holds it, that would reduce it. Say which half of the problem padding would cover and which half it would not.
Extend. Return to The knowledge split, live and watch the exchange one step at a time instead of jumping to the end. If the page still holds the query you invented in class, leave it; on a freshly loaded page the box is back to the lab's own example, so put an invented query in its place. Either way, do not type a real search of your own, a real name, or anything else about yourself. Press Run the exchange, then press Next step repeatedly until it stops advancing, reading the status line under those buttons after each press: it names the step and says what is travelling at that moment. Write down, in the page's own words, what the status line says is on the wire at the step where the relay hands the request on, and at the step where the gateway opens it, and compare those two lines with what you recorded on the Relay and Gateway cards. Note that re-running clears the results from the earlier panels.
Extend. Compare the four padding rows in your Record table — unticked and ticked, each joined on size and on timing. Say what ticking Pad every request to 256 bytes (RFC 9292 §3.8) changed and what it left unchanged, then open What padding does and does not fix in the panel Correlation without collusion again and use the page's own explanation to say what the person reading both logs used in each case. What does that suggest about a request log described as "encrypted"?
Extend. Go to the panel Break it yourself and press 3 · Decrypt with the gateway's leaked key; the attack buttons stay disabled until an exchange has been run, so run one first if the page has been reloaded. Read the paragraph above the boxes, then write down what the Cryptographic result box and the Privacy verdict box each say. This is the case where a decryption that works is the bad news: explain why success is the bad outcome here, and say which single party ended up holding both facts that the design had been keeping apart. Connect your answer to the Client card "cannot know" line you quoted in Explain question 3.
Extend. Return to The knowledge split, live, set Request shape to the POST option, type a different invented note into the input box, and press Run the exchange again, then Jump to end. Compare the Gateway card with the one you recorded. Say what the card shows and what it does not show, then use the step description that says the gateway "reads your request in full" to decide whether your note was hidden from the gateway or merely not displayed. Note that re-running clears the results from the earlier panels.
Extend. In Break it yourself, press 1 · Decrypt with a key you generate and then 2 · Flip one byte, then forward it, and read what each reports. Using the page's own paragraph under each result, say what a dishonest relay can still do to a patron's request even though it cannot read it, and what that would look like to the patron.
Extend. Read the panel Honest scoping — what this lab does and does not show, together with the footnote under the two logs about the arrival clock. List which of the things you recorded were real cryptographic values and which were simulated, and say how that changes what you would be willing to claim about this exhibit in a class presentation.
About 24 minutes of class time; Predict is pre-class reading and Explain is a spoken debrief
Checked against
Lab commit abca4df106c0 on 2026-09-22
NameDate
Predict
Answer these before you open the exhibit. There are no penalties for wrong predictions; the point is to compare them with what you see. Nothing here needs arithmetic beyond an average.
A payroll office promises it will publish only totals, never one person's pay. In the same week it publishes two of them: the total payroll, and the total payroll for everyone except one named employee. Write down what a reader who sees both can work out about that employee, and say whether the reader needs to know anything about the other people on the payroll in order to do it.
Now the office adds a random amount to each total before publishing it, and says so. Predict whether subtracting the two published totals still gives that employee's pay exactly, roughly, or not usefully at all. Then say what you would look for on screen to tell which of the three you are seeing — you will be able to run the same subtraction several times over.
Before a total can be published this way, somebody has to declare in advance the most that any one person's salary will be allowed to count for. Predict what happens to the published total if that declared cap is set lower than what the best-paid people actually earn, and what happens to the size of the random amount if the cap is set very high.
A reader is allowed to ask for the noisy total as often as they like, and averages all the answers they get back. Predict how that average compares with any single answer, and say what that would mean for the promise the randomness was added to keep.
Do
Open the exhibit. It opens on the guided route: in the navigator headed The core path, check that Guided lesson is the route shown as selected. Leave Classroom mode — reproducible, seeded sampling, at the foot of the opening section, unticked, so the numbers you record are your own. Do not move any ε control anywhere on the page while you work — every reading below assumes the value the page starts with.
Go to the section headed Two harmless totals, one person's salary. Under Predict first, press the option that matches your answer to Predict question 1 and read the explanation the page gives for the option you chose. Then, in the card headed The database, find the row tagged the target and copy her name and her salary into the first table under Record.
In the card headed The differencing attack, leave How the two totals are answered on Exactly — no noise, the broken mode and press Run the attack. Record the two totals the page lists, the difference it reports underneath them, and the headline of the verdict. Then open the disclosure inside that verdict and read its two paragraphs on what would not have helped.
Change How the two totals are answered to With differential privacy at ε = 1. The attack re-runs on its own. Record the new headline, the noise scale named in the verdict's second paragraph, and the five values in the chips labelled run 1 to run 5.
Press Run the attack again without changing anything else, and record the second headline and the second set of five values. Note whether the verdict says any run landed close to the true salary, and what it says about that.
Go to the section headed Composition: ε is a budget, not a setting. Under Predict first, press the option that matches your answer to Predict question 4 and read the explanation. On this route the attack comes before the defence, so the card below it is The averaging attack — what happens with no budget at all.
Leave Number of times to ask, at ε = 0.5 each where it starts and press Run the averaging attack. It is finished when that button becomes pressable again. Record Queries asked, Running average, Error and ε spent from the row of figures, and the headline beneath them.
In the card below it, The ledger, leave Total ε budget for this session on its opening setting. Press Ask: total payroll (ε = 0.5) and keep pressing it until the page stops answering. After each press record whether an answer came back and the Charged and Remaining figures. Read the verdict that appears when it refuses.
Record
Every value below comes from your own run.
From the printed database
What it says
The name in the row tagged "the target"
blank for your answer
Her salary, as the table prints it
blank for your answer
How the two totals were answered
Total payroll
Total payroll excluding her
The difference
Headline of the verdict
Exactly — no noise
blank for your answer
blank for your answer
blank for your answer
blank for your answer
With differential privacy, first press
blank for your answer
blank for your answer
blank for your answer
blank for your answer
With differential privacy, second press
blank for your answer
blank for your answer
blank for your answer
blank for your answer
With differential privacy
First press
Second press
run 1
blank for your answer
blank for your answer
run 2
blank for your answer
blank for your answer
run 3
blank for your answer
blank for your answer
run 4
blank for your answer
blank for your answer
run 5
blank for your answer
blank for your answer
Noise scale named in the verdict
blank for your answer
blank for your answer
The averaging attack
What the page reported
Queries asked
blank for your answer
Running average
blank for your answer
Error
blank for your answer
ε spent
blank for your answer
Headline
blank for your answer
Press of Ask: total payroll (ε = 0.5)
Did an answer come back?
Charged
Remaining
First
blank for your answer
blank for your answer
blank for your answer
Second
blank for your answer
blank for your answer
blank for your answer
Third
blank for your answer
blank for your answer
blank for your answer
Fourth
blank for your answer
blank for your answer
blank for your answer
Explain
Compare the difference your exact run produced with the salary you copied from the printed table. Both queries the attacker asked were ones the system was built to answer. Say what the two had in common and what they differed in, and why that difference is one person. Then use the disclosure you opened in step 3 to say why a rule that only approved queries about large groups would not have stopped it.
Your runs with noise gave a spread of values rather than one. Using the noise scale the verdict names and the salary you copied down, say what a reader who saw only those five numbers could honestly claim about her pay. The verdict may report that a run landed close; the page says why that is not something an attacker can use, so put its reason in your own words. Then compare your values with a classmate's and, using the page's own note about where its randomness comes from, say why those five differ — and name one figure you recorded that was the same for both of you.
Every answer in the averaging attack was, on its own, a correctly private release, and the page says so. Using your row from that table and the verdict the ledger gave when it refused, say what the reader walked away with, where the page locates the failure, and why refusing to answer is treated as the right behaviour rather than a breakdown. Then read the recap card headed One thing the pictures can mislead you about and name one conclusion about the people in this payroll that stays available to a reader even when each of them individually is protected.
Fix / Extend
Fix. A library consortium publishes each month the total fines owed across all its member libraries, and the total fines owed by every member except one named branch. Using your records from Exhibit 1, say what a reader of a single month's figures can work out. Then name the three changes this exhibit makes to a published total so that they cannot, and for each one say who has to decide it and whether that decision happens before or after anybody looks at the data. Extend 3 and 4 below work through one of the three on the page; do those first if you have not already.
Fix. A vendor tells your library that its reading-history analytics are "differentially private at ε = 1, so no individual can be identified". Using the section headed What this demo does and does not prove and the verdict the ledger gave when it refused, write two questions you would need answered before you could evaluate that claim, and for each one name the party who has to be trusted for the answer to hold. Then open Jargon, unpacked in the opening section, read the entry for ε, and say why the vendor's sentence as written claims something ε does not measure.
Extend. Open the exhibit on the guided route — Guided lesson, in the navigator headed The core path — and leave every ε control where the page starts it. Go to the section headed Where does Δ come from? You have to answer and work Declared upper bound on one person's salary through all four of its settings, noting for each one Sensitivity Δ, Noise scale b = Δ/ε, Records clipped and Clipping bias from the row of figures below the menu. Describe which way each of the two costs — the noise scale, and the clipping bias — moves as the bound rises, and say which of the two would still be there after a reader had averaged a great many published totals. Then find the note under that row of figures which says where the bound may not come from, and give the reason the page gives for it. Compare all of it with what you predicted in Predict question 3.
Extend. Still on the guided route, in the section headed Where does Δ come from? You have to answer, set Declared upper bound on one person's salary to $250,000 — declared in advance and read the line about the thirteenth person to join the payroll. Press Clip her to the declared bound, then Drop her record from this release, then Raise the bound so it fits her, noting the headline each one produces and, where the page reports them, Δ used, Systematic bias and Still ε-differentially private — one of the three is refused and reports none of those figures. Using the page's stated reason for that refusal, say what the refused option would make the size of the noise depend on, and why that is a problem even though that option introduces no bias at all. Then say which of the other two you would choose for a payroll figure your library published, and what you would have to publish alongside the number for it to mean what a reader would take it to mean.
Extend. In The ledger, change Total ε budget for this session to 3, which starts the session's accounting again, then press Ask: total payroll (ε = 0.5) until it refuses once more. Say how many answers you got this time, and what changing that setting changed about the promise being made to the people in the database rather than about the mechanism. Open the refusal's disclosure and quote the sentence that says so.
Extend. Below the averaging-attack chart there is a disclosure holding the plotted numbers as a table. Open it and read the error column and the ε column together, from the top of the table to the bottom. Say what each column does as the number of queries rises, and which of the two ever stops on its own.
About 25 minutes of class time; Predict is pre-class reading and Explain is a spoken debrief
Checked against
Lab commit 66c860a4a312 on 2026-09-22
NameDate
Predict
Answer these before you open the exhibit. There are no penalties for wrong predictions; the point is to compare them with what you see.
In this design the catalog holds 64 records, and a patron's request is a list of 64 numbers: a 1 at the position of the book they want and a 0 at every other position. Each of the 64 numbers is encrypted separately before it is sent, so the catalog server receives 64 encrypted numbers and no position. If you were shown those 64 encrypted entries and told that exactly one of them hides the 1, how often would a guess be right? Write the fraction, and say whether you think staring at the encrypted bytes could beat it.
Encryption normally draws fresh random values for every single thing it encrypts. Predict what happens to those 64 encryptions if every one of them is made with the same random values instead: would the encryptions of 0 still look different from each other, and would the one encryption of 1 stand out?
Two ways to build a catalog that does not learn which book you asked for. One needs two separate operators who never compare notes. The other needs one operator and a hard mathematical problem. Predict which is cheaper to run — fewer bytes sent, less time spent — and which asks less of the people running it. Say which of the two assumptions you would rather a library depend on, and why.
Suppose the catalog genuinely never learns which book was requested. List three things that someone watching the network between the patron and the catalog could still write down.
Do
Open the exhibit. It opens on The Shelf. Leave Record size at 512 bytes and Shelf length at 64 records for the whole worksheet.
Under Pick a book, press the button for one book on the shelf. Do this once, now. Write down the position number and the title. Then read the card headed The record the protocol will return and note that what comes back is the record itself, not a yes-or-no answer.
Open The Server's View. Under What you send the page draws your list of 64 numbers in the clear, then a grid of opaque tiles below it, one tile per shelf position, and a line reading "Pick a tile. Which one encrypts the 1?". Press the tile you think hides the 1. Record your guess, and what the page said, in the first row of the first table under Record.
Move to the card headed Break it yourself. It holds one switch, and directly under it a red panel that begins "Deliberately broken." Turn that switch on. The tiles above are redrawn. Look along their hex and record, in the second row of the first table, how many of them now look alike. Pick the odd one out, press it, and record that guess too.
Turn that switch back off, so the encryption goes back to the way the protocol actually works.
Still under Break it yourself, press the filled button whose label says how many trials it will run. It runs one crude attack twice over: once against encryptions made with fresh randomness and once against encryptions that reuse it. Wait for the two result boxes and fill in the second table from them, including the chance figure the page prints beside the first box. Then open the disclosure at the foot of that card and read its three paragraphs; you will need them in Explain.
Open One Server vs Two. In the card headed Run both protocols over the same shelf, press the filled button that runs both of them. Fill in the third table from the comparison table that appears, including which cell in each row carries the word "better".
In the same card, the page now says "The two-server scheme rests on one assumption. Press the red button to spend it." Press it. Record, in the fourth table, the shelf position it names beside the position you chose in step 2.
Open What It Does Not Hide. Under What a network observer sees the page says "The observer has seen nothing yet. Run a few queries — try different books." Do that: press the filled button — the one that queries a random book — three times. Record the three rows of the observer's log in the fifth table, and read the two boxes underneath it.
Still on that tab, read the table under What is hidden, and by what and copy the status and the "Where that comes from" cell for the four properties listed in the sixth table.
Record
Every value in these tables comes from your own run.
Encryption
Tile I picked
Right or wrong
Position the page said held the 1
How many tiles looked alike
Fresh randomness, switch off
blank for your answer
blank for your answer
blank for your answer
blank for your answer
Randomness reused, switch on
blank for your answer
blank for your answer
blank for your answer
blank for your answer
Reading from the trial boxes
Value
Trials run
blank for your answer
Fresh randomness, number correct
blank for your answer
Fresh randomness, percent
blank for your answer
Reused randomness, number correct
blank for your answer
Reused randomness, percent
blank for your answer
The chance figure printed beside the fresh box
blank for your answer
Row on the comparison table
One server, RLWE
Two servers, XOR
Which cell is marked "better"
Servers required
blank for your answer
blank for your answer
blank for your answer
Trust assumption
blank for your answer
blank for your answer
blank for your answer
Privacy
blank for your answer
blank for your answer
blank for your answer
Upload per query
blank for your answer
blank for your answer
blank for your answer
Download per query
blank for your answer
blank for your answer
blank for your answer
Records touched
blank for your answer
blank for your answer
blank for your answer
Can the answer be wrong?
blank for your answer
blank for your answer
blank for your answer
Reading
Value
Shelf position I chose in step 2
blank for your answer
Position the two servers named after comparing notes
blank for your answer
Query
At (ms)
Uploaded
Downloaded
Book (not observable)
1
blank for your answer
blank for your answer
blank for your answer
blank for your answer
2
blank for your answer
blank for your answer
blank for your answer
blank for your answer
3
blank for your answer
blank for your answer
blank for your answer
blank for your answer
Property, as the page names it
Status
Where the page says that comes from
Which record was requested
blank for your answer
blank for your answer
That a query happened
blank for your answer
blank for your answer
When it happened
blank for your answer
blank for your answer
Who is asking
blank for your answer
blank for your answer
Explain
The lab's own README states the threat model these questions work inside: an honest-but-curious server that follows the protocol and tries to learn the position from what it receives, and a passive network observer that sees traffic but no plaintext.
Your guess in step 3 was one tile out of 64, and the page told you straight away whether it was right. A single result like that cannot settle whether the encryption is doing its job, in either direction. Using the two counts in your second table, say what the repeated trials establish that one guess cannot, and say what the chance figure you recorded is the chance of.
Between your two guesses nothing about the attack changed: the same eyes, the same tiles, the same question. Using what you recorded in the first table and the three paragraphs in the disclosure you opened in step 6, explain what reusing one set of random values does to 64 encryptions of 0, and why that makes the single encryption of 1 findable by someone who has no key at all.
Look at your third table. The two-server column wins every row that is a cost. Name the two rows where it does not win, say in your own words why the page calls those two rows the same fact said twice, and say what the red button in step 8 did to the two-server column's advantage.
Fix / Extend
Fix. A vendor offers your library a private catalog search and says the search service never learns which title a patron looked up. Using your third table and the card headed Honest scope on What It Does Not Hide, write the two questions you would put to that vendor before believing the sentence: one naming the assumption the claim rests on, and one naming the party who has to be trusted for it to hold. For each, say what answer would satisfy you and what answer would not, and say which of the two designs in your third table the vendor's answers would place them in.
Extend. Open One Server vs Two and, in the card headed What the numbers do not say, open the disclosure at the foot of that card. The second of its three paragraphs describes running two servers under genuinely separate control as "an organisational problem, not a technical one". A patron standing at a catalog terminal can see neither operator's records. Using that phrase and your fourth table, filled in step 8, say what such a patron could check for themselves about whether the two operators are staying apart, and what they would have to take on trust instead. Then open What It Does Not Hide, read the card headed Honest scope, and say what the one-server column asks you to believe in place of non-collusion, and what that card says this page does not prove.
Extend. Your observer log, recorded into the fifth table in step 9, has columns that came out identical across the three rows and a column that did not. Open What It Does Not Hide and go back to the card headed What a network observer sees; if its log is empty because the page was reloaded or a setting changed since, press the filled button — the one that queries a random book — three times again, so the two boxes under the log are on screen. Using your three recorded rows, those two boxes and the four properties in your sixth table, say which single fact about a patron's request this design keeps from a network observer, and list what it leaves that observer holding. Then pick one item from that list which a library could reduce by something other than encryption, and say what the page suggests would reduce it.
Extend. Open Homomorphic Selection and use the buttons in the card headed The homomorphic inner product to fold the records into the answer one at a time, then eight at a time, then the rest. Watch the running answer and the measured budget as you go. Before the record you chose has been reached, what does the page say the accumulator decrypts to — and why does the budget fall anyway? Use the page's own three-line account of why the sum does the selecting.
Extend. Back on The Shelf, in the card headed This run, type a string into Run seed and press Pin this seed. Read the warning the page then prints beside it. Get a classmate to pin the same string and pick the same shelf position, and compare your tiles on The Server's View with theirs. Then say, using that warning, why a real system must never let a run be pinned this way, and how this failure is related to the one you produced in step 4.
Extend. Do this one last, because it discards everything you measured. Open Noise Exhaustion and, in the card headed Push it until it breaks, lower the ciphertext modulus one step at a time, retrieving at each setting, until the page reports a failure code instead of your record. Record the code and the three figures the page reports with it. Then, using the note printed under those figures, say which of those three checks a real patron's own software could run for itself, and which it could not — and say why that distinction is the reason the page insists a deployment sizes its parameters in advance. The card headed The failure codes names the other three codes and what raises each.
Crypto Lab exhibits are teaching demonstrations, not production libraries. Do not use exhibit code to protect real data.