5 ms·
Wrong. "One of the first things anyone learns about Zcash" is that at least one of the ceremony's participants must be trusted to have securely destroyed his t
by hendi_ 8y ago
Wrong.
"One of the first things anyone learns about Zcash" is that at least one of the ceremony's participants must be trusted to have securely destroyed his toxic waste.
This article is about the fact that there could be a backdoor, whose absence can only be proven by revealing all participants' toxic waste.
You'll note that these two things are at odds with each other.
- matthewdgreen 8y agoI don’t think that’s true. The article seems to be saying that you can sneak a backdoor into the circuit. You can also verify that the parameters implement the circuit, and you don’t need the toxic waste to do that.
- _Drygin 8y agoThank you for your comment. Unfortunately I made a mistake. I have removed misleading information from the article.
- ewillbefull 8y agoThere is nothing new about this article. The article is pointing out that in addition to the trapdoors of the proving system, it's possible to subvert the arithmetic circuit used as well. The ceremonies used by Zcash have the property that the parameters are perfectly bound to the circuit. Not sure why this isn't mentioned in the article. > This article is about the fact that there could be a backdoor, whose absence can only be proven by revealing all participants' toxic waste. This is incorrect, as stated above. Instead of revealing their toxic waste, we reveal proofs-of-knowledge so we can use pairings to ensure the parameters encode the circuit correctly.
- hendi_ 8y agoI stand corrected. Thank you for the clarification! I still learned something "new" from the article, I was only aware of the ceremony issue that "everbody knows" of.
- ewillbefull 8y agoThat's great! There are many issues with trusted setups that people aren't paying enough attention to.
- _Drygin 8y agoYou're right, I removed misleading information from the article. Thank you for your comment.