Fedi, I have a design problem I'd appreciate thoughts on.
I've been building a federated E2EE messenger (based on MLS) where the server learns as close to nothing as possible about you, so there's no accounts or user records. Which raised the obvious question: how do you rate limit anything?
The answer I went with is PrivacyPass. You authenticate once to get a batch of tokens, so the server knows who you are at that moment. Then you spend them anonymously - they're blinded at issuance, so when one comes back the server can verify it's valid but can't tell who it gave it to. Rate limiting happens at issuance, not at send time. You get a budget: 2,000 tokens/hour, 10,000 burst. (the numbers are based on napkin math and can be adjusted)
Now the actual problem: one token buys one envelope, and an envelope goes to one device. Group messages fan out client-side, so a message to a group of D devices costs D tokens. At two devices per person, a 250-person group is 500 tokens per message which is about 4 messages/hour. So groups pretty much have to cap out around 200-250 people.
I can't just make fan-out cheaper, because the server can't see group membership. It genuinely cannot distinguish "500 envelopes because my group is large" from "500 envelopes because I'm spamming 500 strangers." Any discount that makes fan-out affordable makes spam affordable by exactly the same factor.
The only structural escape I've found is to stop fanning out - one envelope that many people fetch. But then the server sees N people reading one mailbox, which hands it the group membership the per-recipient design exists to hide.
So:
- Is there a way to prove "this batch is fan-out to a group I belong to" without revealing the group or its members? Feels anonymous-credential-shaped but I haven't found the primitive.
- Is ~250 people a reasonable ceiling to just accept?
- Anything obvious I'm missing?