|
|
|
|
|
by plasticmachine
3882 days ago
|
|
On further consideration I agree with you. Knowledge of the accumulator would merely allow for the arbitrary creation of forged spends that appear valid, but the rest of the system would still remain opaque (much to its detriment in this instance). Also there is nothing so suggest that a clever MPC will solve the collusion problem. Of course the participants will make claims about their honesty, but if ZeroCoin is worth massive amounts of money the temptation to seek collusion will be there. Of course, whilst it's true that some participants might stick to their proverbial guns, what is going to prevent a motivated state-level attacker from monitoring as many participants as they can during the computation? Then they only need to compromise the handful that they couldn't monitor, and for that they have rubberhose cryptanalysis. |
|