A non-validating notary receives inputs in the form of Corda StateRefs. What information can be reversed engineered from a StateRef and what additional information would an attacker need to be successful in doing so?
For more context, please see the answer to the question, In Corda, what data is sent to a non-validating notary service? posted by @joel which explains that the inputs in the form of StateRefs are sent to a non-validating notary.