CONCEPT Cited by 3 sources
Non-targetability¶
Definition¶
Non-targetability is the security property that an attacker cannot single out a specific individual's session, request, or storage without compromising the entire system. It raises the cost of a targeted attack from "subvert one user's traffic" to "subvert the whole population," which is both far more expensive and far more likely to be detected. It is the deliberate design goal of removing the "route this particular person to a compromised machine" attack from the menu.
Meta states the requirement verbatim: "An attacker or malicious actor must be incapable of targeting a specific individual's session or storage without attempting to compromise the entire Private Processing System." (Source: sources/2026-09-24-meta-bringing-private-processing-to-meta-ai-glasses)
Why it matters¶
Even a system with strong confidentiality (a TEE, end-to-end encryption) can be defeated if the operator can route a chosen victim's traffic to a compromised node. If the infrastructure knows who is sending a request, an insider or attacker with control-plane access can steer that request to a machine they have subverted — the confidentiality guarantee holds for everyone except the person you targeted. Non-targetability closes this by ensuring the routing/authentication layer does not know who is being served, so no per-victim steering is possible.
The mechanism (how it's built)¶
Non-targetability is assembled from several independent primitives, each closing part of the identity-to-node linkage (Source: sources/2026-09-24-meta-bringing-private-processing-to-meta-ai-glasses, sources/2025-04-30-meta-building-private-processing-for-ai-tools-on-whatsapp):
- Anonymous credentials, fetched on randomized schedules. Blind-signed tokens (Meta's Anonymous Credential Service) prove the caller is an authentic client without identifying the account; fetching them on randomized schedules prevents timing correlation back to a user.
- Third-party OHTTP relay. The device connects through an Oblivious HTTP relay (Meta names Fastly and Cloudflare for the glasses deployment) so the relay sees the client IP but not the inner request, and the gateway sees the inner request but not the client IP. No single party holds both halves.
- Non-user-identifiable node selection. The TEE node servicing a request is chosen on heuristics that carry no user identity, so even the selection step cannot be steered per-victim.
- No identifiable information in the session. The request establishment carries no other account-linking data.
These compose so that identity is stripped before any routing decision is made — the operator literally lacks the information required to target one user.
Relationship to sibling concepts¶
- concepts/blast-radius — non-targetability inflates the attacker's blast radius on purpose: because you cannot attack one user cheaply, any attack must be system-wide, which is expensive and conspicuous. It's blast-radius reasoning turned into an offensive-cost lever.
- Unlinkability — the anonymous-credential property (issue and redeem events can't be correlated to one user) is a building block of non-targetability; non-targetability is the higher-level system guarantee it enables.
- concepts/defense-in-depth — non-targetability is one of the stacked requirements of a private-AI-inference system; it closes the targeted-host attack path specifically, complementing attestation (runtime-binary path) and transparency (supply-chain path).
Seen in¶
- sources/2026-09-24-meta-bringing-private-processing-to-meta-ai-glasses — non-targetability is one of five engineering requirements for AI-glasses Private Processing; built via anonymous credentials on randomized schedules + Fastly/Cloudflare OHTTP relays + non-identifiable TEE selection. Canonical wiki instance.
- sources/2025-04-30-meta-building-private-processing-for-ai-tools-on-whatsapp — non-targetability is a foundational requirement of the original WhatsApp Private Processing; "an attacker cannot target a particular user without attacking the entire Private Processing system."
- sources/2026-08-12-meta-how-were-building-scam-alert-on-whatsapp-with-end-to-end-encryption-and-verifiability-guarantees — non-targetability for model delivery: OHTTP + anonymous credentials + on-device experiment self-assignment ensure no targeted model can be pushed to a specific user.
Related¶
- concepts/defense-in-depth — non-targetability is one stacked layer, closing the targeted-host path.
- concepts/confidential-computing — the posture non-targetability protects against operator-side steering.
- concepts/trusted-execution-environment — confidentiality boundary that non-targetability keeps un-steerable.
- concepts/blast-radius — the offensive-cost framing (force whole-system attacks).
- systems/meta-acs-anonymous-credentials — the anonymous-credential primitive.
- systems/whatsapp-private-processing — the canonical deployment.
- third-party-ohttp-relay-for-unlinkability — the routing-layer pattern (recorded as prose across the Private Processing sources) that enforces it.