Hacker News new | ask | show | jobs
by saagarjha 690 days ago
I don't think the set of bad numbers needs to be encrypted.
1 comments

It does - otherwise you would know which numbers are queried to process the query, letting you narrow things down (ie huge side channel and thus not HE anymore).
How so? You can just query all the numbers and discard results you don't want.
Sure, you can query the database all you want. The important property is that the server cannot observe the client querying the database - processing a query occurs in an encrypted space that it does not have the keys to. Similarly, one would expect that each query, even if it's for the same phone number, would be observed to be reading randomly from the database each time.