Hacker News new | ask | show | jobs
by XMPPwocky 2293 days ago
You could also do it modulo some number, I think?

Then knowing any individual number (weight + pad) mod n gives zero knowledge (I think. If all but one party reveal their pads, they can trivially determine the other's weight so it fails. Believe it to be secure if only 1 party is malicious, though. Cases for other numbers of bad actors are more complicated...)