Earlier quoted context omitted.
I appreciate that, but: 1. If google is paying fastly, what prevents google from paying fastly some more to divulge the user information as well? As far as I understand ohp, the model assumes that the three parties are not aligned which is not true for the fastly:google connection. 2. Even 1. is not true, if the encrypted body is not salted, it is effectively just a unique hash of the original url, which means that f…
I don't think your #2 is a concern as OHTTP uses HPKE ( https://blog.cloudflare.com/hybrid-public-key-encryption/ ).
My cryptography education is rather superficial, so I might be missing something.