33 ms·
Confess your love with zero-knowledge
- tinktank 4y agoPretty clever IMO
- Tomte 4y agoThis is some strange notion of zero-knowledge. If Bob publishes his link, and I want to know who his crush is, I can simply try all our classmates' names and quickly find out that it's Alice. Those games only make at least a bit of sense when everybody enters their crush and only when matching both get notified. Also brute-forceable, but at least it's quadratic (if you suspect nothing about crushes, which is unrealistic in itself).
- praptak 4y agoYeah, it is like hashing a phone number to protect its owner's identity. With a small domain known by the attacker hashing isn't really one-directional.
- lvass 4y agoOr even easier, use a SHA-256 reversing service that has all names.
- random314 4y agoOr just tell your crush, without sharing URLs with everyone
- staticassertion 4y agoEasy as an adult. But as a kid I feel like we jumped through soooo many hoops to de-risk telling someone we had a crush on them. I remember those reallllly early games like MASH or even early "compatibility" apps. Very coy.
- the_af 4y agoYes, I can see how -- as a kid -- sharing an URL of your hashed crush with the world is not going to be awkward at all.
- soco 4y agoPutting links in your tiktok/whatever profile doesn't seem like very unusual nowadays...
- staticassertion 4y agoAwkward is the name of the game.
- vintermann 4y agoThere's nothing wrong with only wanting to reveal a crush if it's somewhat returned. If it isn't, you're just putting them in an uncomfortable position for no good reason.
- random314 4y agoAnd this hash url absolutely doesn't solve this problem
- imagin8or 4y agoI feel like this could be a good implementation. "Find out if your crush fancies you, just choose them from your contacts:" ... "Message 'hey there, I like you' sent"
- tgv 4y agoIf it tells you how many letters are right, and how many are in the right place, it could become Datle.
- andrewstuart2 4y agoChallenge: build something worthy of being called 204Date (2048 clone).
- jandrese 4y agoSmashing together people to win at dating? Isn't that just Tinder?
- CameronNemo 4y agoTinder goes in two directions. This would go in 4 directions. Swipe up to send them to your friends, down to your enemies, left to the void, right to you.
- bonzini 4y agoMatch fruits until you get a date?
- dylan604 4y agoCareful, FruitNinjaDating could get interesting if not messy
- darig 4y ago
- dane-pgp 4y agoYou start with 2048 single people, and have to act as matchmaker to pair them off into married couples who each produce at least one child. A generation later, you take the 1024 first-borns of each couple and have to pair them off too, into 512 new pairings. Repeat that long process until there is just one couple left, whose first-born you then propose to. Having lived long and healthily enough to complete this game, you must have some very desirable genes and/or wealth, and you'll be good friends with basically all this person's ancestors, so there's a strong chance they'll say yes, despite the age difference.
- spekcular 4y agoIndeed, a similar "secure" crush confession on an MIT facebook group was exploited in this way, by brute forcing every name in the student directory.
- LeifCarrotson 4y agoYou'd want to use asymmetric public key cryptography so that Bob could hash his message with Alice's public key, and it could only be decrypted with Alice's private key.
- deleted 4y ago[deleted]
- superjan 4y agoFor heaven’s sake just call her!
- tawktiem 4y agoYup, everyone publishes their public keys. No one’s private keys gets published (fake crush created). I’m not sure if zero-knowledge proofs exist for love outside of action - repeated acts of commitment over time (to reduces the confidence that someone doesn’t love you).
- gizmo686 4y agoThat still lets Alice find out. I don't see a clear way of mapping the concept of a zero knowledge proof to the crush problem. But the best I can come up with is: 1) No one learns that Alice (claims to) have a crush on Bob 2) Unless Bob also claims to have a crush on Alice, in which case. 3) Only Bob learns that Alice has a crush on him. 4) If Bob learns that Alice has a crush on him, Alice learns that Bob has a crush on her. 5) All the above guarantees are symmetric if you swap Bob and Alice.
- geysersam 4y agoSeems to me such a system must make it expensive to claim to have a crush on someone. Otherwise Bob can just claim to have a crush on everyone and will find out who crushes on him.
- vintermann 4y agoThat lets Bob confess semi-deniably to Alice (if Alice is willing to share her private key, she can still show Bob's confession to Carroll and prove that it's authentic). But it still doesn't do any matching; Alice will know about Bob's feelings whether she returns then or not.
- momojo 4y agoThis could be a fun way to teach a class about the vulnerabilities around hashing. Strong hash != strong protection. Maybe the second half of the class could be about designing a more secure system. Or use this dilemma to explain public-private key encryption.
- mikebenfield 4y ago> Those games only make at least a bit of sense when everybody enters their crush and only when matching both get notified. Even then, among heterosexuals they will suffer from the same problem as basically every software platform for romance among straight people: the massive asymmetry in interest between men and women. Men would copy and paste virtually every woman they know into the system as a "crush," so they can find which if any of their female acquaintances might be interested, and then they would decide who to pursue.
- pessimizer 4y ago> Men would copy and paste virtually every woman they know into the system as a "crush," so they can find which if any of their female acquaintances might be interested, and then they would decide who to pursue. Smart men would, who know their place in the world. Any of them are good enough for you, really. Take the one that you like the most out of the ones who like you. Is this a problem? If it weren't asymmetric, it would be hopeless. Instead, most men get the choice between one or more interested women, and most women get a response from one or more of the men they were interested in. It's better if one side isn't as picky as the other. The other options are that only a couple of people match up at all, or everyone getting a response from everyone i.e. no signal at all. edit: I mean, isn't that Bumble?
- mikebenfield 4y agoI don't follow this, either logically or in practice. Granted I've never dated as a gay man or as a lesbian, but from what I've observed it seems to me a much smoother and more mutual process than straight dating. I've even heard from bi men about how much easier and less stressful it is to date men than women. AFAICT when both parties are on a level playing field, and there's not a massive asymmetry in power, interest, and investment, there's a lot less grief overall. > edit: I mean, isn't that Bumble? Bumble is a valiant attempt to fix this issue but it seems to mostly be a failure. An average man may occasionally get a message (which will usually just say "hi"), but the asymmetry in interest is still there, and it's still mostly men's responsibility to do the real initiating.
- hinkley 4y agoAnd when everyone is an actual adult, not a manchild or other people without a fully formed prefrontal cortex and thus prone to making ugly, life-changing decisions - for themselves and others - on a dime. That's most of the demographic for this product. The number of over-25 people, not in a committed relationship, who still haven't figured out how to ask people out, is pretty small.
- joebob42 4y agoI dunno. I'm reasonably well adjusted and apparently even decently attractive, and I still have a super hard time with the whole asking people out thing. I've been lucky enough to have people ask me out but otherwise I'm not sure I'd have had much luck dating at all. This tool doesn't do what I'd want, but a tool that did would be kinda neat :)
- a-dub 4y agothat's because it's not zero knowledge, it's password hashing. a zero knowledge proof would do something like prove a valid attestation of love, but reveal nothing about who (other than maybe membership in some large enough set).
- PaulDavisThe1st 4y agoBob's crush, though, works at the ice cream store on the corner.
- skrebbel 4y agoI sent it to my wife but she spelled her own name wrong and now she thinks I have a crush on someone else
- 0xedb 4y ago
- andrewstuart2 4y agoOP should probably trim whitespace too. I sent it to my wife and it's not a match either, because there was a trailing space left by her keyboard.
- anthropodie 4y agoNow you either gotta point out her mistake or you gotta admit you have crush on someone else. Good luck getting out of this :)
- skrebbel 4y agoI told her I have zero knowledge of any of this
- 4y ago
- deleted 4y ago[deleted]
- m00dy 4y agoI hardly see how this is related to zero-knowledge
- ghayes 4y agoYeah zero-knowledge is supposed to give you no usable information, but brute-forcing aside, the fact anyone can learn they are not the target is knowledge, right?
- m00dy 4y agoright.
- motohagiography 4y ago> the fact anyone can learn they are not the target is knowledge, right? To a point, however, you've also described a Bloom filter reasonably well. That is it would show whether their hash is not in the set.
- deleted 4y ago[deleted]
- woojoo666 4y agoI believe "zero knowledge" refers to the third party here. That is, you give it A => B, and it tells you if B => A was given previously, without it knowing the actual values of A or B. While you might be able to brute force the system by trying every name you know, the third party can't unless you give the third party a registry of names to try. Related is the humorous paper "Solving the Dating Problem with the SENPAI Protocol" [1], though the solution in that paper does not rely on a third party. [1]: http://sigtbd.csail.mit.edu/pubs/2016/paper10.pdf http://sigtbd.csail.mit.edu/pubs/2016/paper10.pdf
- sixhobbits 4y ago"First and Last name capitalised" Seems like someone hasn't read the famous "Falsehoods Programmers Believe about Names"[0] [0] https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-believe-about-names/ https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-...
- lvass 4y agoMaybe they did, got confused and gave up. How would you deal with 4, 11, 12+13, 14 and 18 here?
- soco 4y agoQuite simple: you don't deal at all. That's zero assumptions about the name. Let them eat cake and enter whatever they want. The user should know their sweetie well enough to guess what they will enter as own name. This is an assumption about their level of mutual knowledge, true, but not one about the naming scheme.
- lvass 4y agoThis is a design decision that will very likely lead to missed matches, bold of you to assume it's desirable but even that doesn't answer the entire ordeal. How are they going to enter the name, have you read 11?
- not2b 4y agoOn the contrary, there is a very strong and completely invalid assumption: that Alice will type her name in exactly the way Bob typed her name, and vice versa, that neither will misspell it, that either both will use the official name or both will use the same nickname.
- kube-system 4y ago> 4. People have, at this point in time, one full name which they go by. The relationship between person and name is one-to-many > 11. People’s names are all mapped in Unicode code points. You can implement custom characters, i.e. https://en.wikipedia.org/wiki/Private_Use_Areas https://en.wikipedia.org/wiki/Private_Use_Areas or have a process for exceptions > 12. People’s names are case sensitive. 13. People’s names are case insensitive. You can store this as an attribute > 14. People’s names sometimes have prefixes or suffixes, but you can safely ignore those. This can be other fields if you're trying to structure the data, or you can simply store the entire name as a contiguous field. > 18. People’s names have an order to them. Picking any ordering scheme will automatically result in consistent ordering among all systems, as long as both use the same ordering scheme for the same name. Don't string compare names as a test for equality. The obvious response to this is: that's too hard (/impossible to do). But that's just the reality of the situation. These issues are not necessarily possible to solve. #21 in particular makes this application very broken even with very plain vanilla western names.
- natly 4y agoI think this is the first time I've understood zero-knowledge communication.
- go_to_moon 4y agoThis isn't zero knowledge, like, at all "The essence of zero-knowledge proofs is that it is trivial to prove that one possesses knowledge of certain information by simply revealing it; the challenge is to prove such possession without revealing the information itself or any additional information."
- lvass 4y ago"In cloud computing, the term zero-knowledge (or occasionally no-knowledge or zero access) refers to software services that store, transfer or manipulate data such that it is only accessible to its owner, not to the service provider."
- drdaeman 4y ago> In cloud computing Your quote heavily misspells "bullshit marketing" ;) For marketing reasons, people try give things fancy names, even if those names are misused and are completely wrong. This is exactly what happened with all those "zero-knowledge encrypted cloud storages" and so on.
- agucova 4y agoThis seems to imply terms can only have and only one “right” definition, which is not how languages work, at all. Clearly there are two big clusters of meaning for “zero-knowledge” and they seem distinct enough to not overlap. Seems fine to me.
- drdaeman 4y agoWell, you're right. My problem is that they started doing this my using "zero knowledge" as a term from cryptography. The trend had started in early 2010s or so, as cryptocurrencies and all things crypto became popular, people realized they could use that vibe for profit. So cloud storage providers in particular had realized "zero knowledge" sounds cool and fancy and started using it in their marketing despite stealthily assigning it entirely different meaning from where they took it from (well, some had their cryptographic designs all backwards recognizably even to my uneducated brain - false promises when most customers don't have sufficient knowledge and awareness, business as usual). They were critiqued for it, and they just shrugged it off because who gives a fuck about some angry nerds insisting on some correct word usage. And so this shit caught on, and yes, now we have two meanings. I suppose I got to let it go, but I feel upset about the outcome.
- runjake 4y agoMaybe this would be better using Twitter/Instagram/TikTok/Snapchat handles? (I don't use 75% of those, but presumably they all use handles.)
- UmbertoNoEco 4y agoNothing says romance like a sha-256 hash. Neruda,take notes.
- rockbruno 4y agoFun concept, but quite easy to use with a malicious intent. It would be better if only people who have a crush on you could use the link (meaning the confession would work both ways)
- latchkey 4y agohttps://www.zkcrush.xyz/api/hello https://www.zkcrush.xyz/api/hello
- latchkey 4y agohttps://github.com/amirgamil/zk-crush/blob/main/pages/crush.tsx#L22 https://github.com/amirgamil/zk-crush/blob/main/pages/crush.... const isMatch = React.useMemo(() => hash === crushHash, [crushHash]); Sure is a lot of work to do a string comparison 'efficiently'.
- system16 4y agoHumorous, but not zero-knowledge at all. They could be on to something here though. Maybe blockchain's "killer app" will be Verifiable Romance?
- cableshaft 4y agoInstead of getting your SO's name tattooed on your body that you'll regret in a few years, you'll instead get your names added to the blockchain...that you'll regret in a few years.
- TobyTheDog123 4y agoDont give them any ideas. The RomanceSmartChain is only a few months out at this rate.
- orthecreedence 4y ago$LOVE is MOONING!! Blake2b + Hybrid PoW chain with LOW TRANSACTION FEES and 4 TX/S THROUGHPUT now CONFIRMING COMMITTED RELATIONSHIPS with blockchain technology! Your relationship isn't valid until there are AT LEAST 36 CONFIRMATIONS on $LOVE chain!!1 Also now supporting ON-CHAIN unique NFTs for couples for low fees!!
- sunshinerag 4y agoLink to white paper please
- dane-pgp 4y ago"Couple to Get Married on the Bitcoin Blockchain at Disney Bitcoin Conference" Sep 23, 2014 https://bitcoinmagazine.com/press-releases/couple-get-married-bitcoin-blockchain-disney-bitcoin-conference-1411513231 https://bitcoinmagazine.com/press-releases/couple-get-marrie...
- radicalbyte 4y agoZero-knowledge describes the OP w.r.t zero-knowledge-proofs.
- SpaceManNabs 4y agoI can see this being somewhat popular on some campuses.
- tecleandor 4y agoPoor John Smith.
- aarondia 4y agoTo stop my friends from using this to guess who my crush is, a fun iteration could be instead of entering the person’s name, you enter the last text you sent, place you met, etc. Something only the two of you would know … and maybe even something romantic :)
- snarkconjecture 4y agoWhat does this achieve that posting "text me and I'll tell you if I have a crush on you" doesn't? Or texting your crush directly? I suppose it's a useful commitment mechanism for proving you aren't telling everyone they're your only crush, but that seems a bit of a niche use case.
- mikebenfield 4y ago1. Since it's an external web site with a little bit of tech behind it that presumably others are using, it might seem less desperate or strange than the post you suggest. 2. The potential crushee can do the check without notifying you they're doing so. They might be too embarrassed/intimidated to actually tell you they're interested in whether you have a crush.
- flax 4y agoI own the domain ilikeyou.fyi and considered doing something very much like this. I rejected that plan for all the reasons above. It could be done better with public/private key cryptography, but then your audience has to be able to deal with that. Oh well, it's on my backlog down in the "I'll never actually get there" section.
- Garvey 4y agoSmall idea, no idea how useful if at all but maybe it could be a simple page with a list of reasons why the sender likes the recipient, and/or a YouTube playlist of songs that remind them of the recipient etc
- batch12 4y agoMaybe don't display the hash and self destruct after n bad guesses or something.
- deleted 4y ago[deleted]
- niyazpk 4y agoWell... hactually... This is kind like the opposite of zero-knowledge, where everyone can know your crush just by entering all suspecting names in the link.
- deleted 4y ago[deleted]
- ihuman 4y agoI remember reading a joke research paper about something like this. It explored all currently known methods of confessing your love, their pros and cons, and had a funny acronym for each. It then proposed a newer, secure algorithm for confessing to your crush if the feeling was mutual, and without leaking information to 3rd parties. I'm trying to find it, but I don't have it saved and I haven't found it on Google yet.
- easton 4y agoThe SENPAI protocol! http://sigtbd.csail.mit.edu/pubs/2016/paper10.pdf http://sigtbd.csail.mit.edu/pubs/2016/paper10.pdf
- ihuman 4y agoThank you! I had a feeling the name had something to do with anime, but I couldn't remember what.
- anticristi 4y agoThis is probably the geekiest CS paper I ever read!
- dane-pgp 4y agoI'm really impressed with how readable and how funny that is, but I'm sure I'm missing at least one of the jokes contained within. In particular, they suggest an extension to their protocol called "SENPAI-MTT (More Than Two)", which I'm sure must be a cleverly chosen backronym, but I can't work out why (or if) it is funny. My initial thought was that it could be a reference to the Japanese verb meaning "to look"[0], such as mite ita ("was looking") but represented in vowelless chatspeak[1]. More logical, though, would be the verb meaning "to notice"[2], but the imperative would be kizuite kudasai ("please notice!")[2], and that doesn't match "MTT" at all. [0] http://www.japaneseverbconjugator.com/VerbDetails.asp?txtVerb=%E8%A6%8B%E3%82%8B http://www.japaneseverbconjugator.com/VerbDetails.asp?txtVer... [1] https://old.reddit.com/r/LearnJapanese/comments/bupbs9/about_leaving_out_vowels/ https://old.reddit.com/r/LearnJapanese/comments/bupbs9/about... [2] http://www.japaneseverbconjugator.com/VerbDetails.asp?txtVerb=%E6%B0%97%E4%BB%98%E3%81%8F http://www.japaneseverbconjugator.com/VerbDetails.asp?txtVer...
- markus_zhang 4y agoInteresting but I'm too old for this.
- easton 4y agoContext: http://sigtbd.csail.mit.edu/pubs/2016/paper10.pdf http://sigtbd.csail.mit.edu/pubs/2016/paper10.pdf
- varispeed 4y agoIt's fascinating to see how far people are willing to go to avoid the awkward feeling of potential rejection. I mean I have been there. But as I am older this just feels funny. If you like someone just tell them. Rejection is part of the fun.
- anticristi 4y agoRight? I embraced rejection therapy and the results were scary good. A whole new world opened up, not only in romance, but sales, financing, recruitment, etc.
- deleted 4y ago[deleted]
- bigdict 4y agoI think this was originally a joke on a MIT Facebook page.
- yosito 4y agoWrapping this in a native app could be a nice little moneymaker. Lots of speed dating events could use this to help match attendees that were interested in each other.
- can16358p 4y agoLove these kind of ideas. Reminded me of once I was trying to allow access to a file with a password. It wasn't any super-secret file or anything, just a CV of a friend hosted on a static file server and she wanted it to "protect" it with a simple password (just didn't want it to be directly available to anyone viewing the homepage. No mission-critical secret of any kind otherwise). Having no real/strict security requirements and being lazy to go server-side scripting, I simply hashed the password. Noted the hash. Saved the file into a folder like "/${hash}/Proper Name.pdf". Hashed the hash again and embedded it into client-side JS. Wrote a JS function that took the input, hashed it twice, and if second hash of the entered password matches that, download the file "/${first hash}/Proper Name.pdf". It worked like a charm, but please note that this is prone to attacks so if anyone reading this thinks it's a good idea to implement actual security, DO NOT. It is not. Fun to play with though.
- jesprenj 4y agoWhat attacks?
- martin-adams 4y agoMaybe the browser or an extension leaking the URL of the file, which could ultimately get indexed in a search engine.
- jesprenj 4y agoFair point, though search engines are aware of special headers that tell them not to publicize the link to the content. Would it be any safer with the key in the GET parameter string? Search engines still usually treat this string as part of the address.
- Godel_unicode 4y agoAmong other things, it’s almost certainly the case that the web server isn’t implementing a constant-time string comparison for the URL, which enables you to brute-force the value one character at a time.
- michaelmior 4y agoAvoiding hash collisions has never been so important…
- hsnewman 4y agoWhat if your girlfriend and wife have the same hash?
- Liron 4y agoLast year my wife and I suspected we might have gotten each other the same Christmas gift, but didn’t want to spoil the surprise in case we didn’t. So we compared SHA256 hashes... and sure enough they both came out cb17007d (theragun)
- garaetjjte 4y agoDoesn't work, because you can reasonably brute-force possible gifts.
- Liron 4y agoYeah I'm not sure what's the best protocol that's actually zero-knowledge here, but since we both trusted each other to only want to find out whether or not our gifts were the same, and otherwise to not spoil the surprise, this did the job.
- kevinventullo 4y agoYou could write a script that does the hash comparison for you and simply outputs “Yes” or “No” for whether the hashes are identical.
- soonerroadie 4y agoYou could just write a script that lets you write an input and your spouse writes an input and then compares the two inputs without showing them - no need for hashing at all.
- lights0123 4y agoYou could reveal the hash letter-by-letter and stop as soon as a letter differs so there's more possibilities.
- teaearlgraycold 4y ago> stop as soon as a letter differs Oops - you just exposed a timing attack side channel
- deleted 4y ago[deleted]
- littlestymaar 4y agoJacques Patarin[1], my cryptography teacher at university introduced us with zero-knowledge proofs with a simple real-life zero knowledge scheme for this exact purpose. All you need is 5 cards, 3 identical red and 2 identical blacks. You give one black and one red to each person (Alice and Bob), and keep the last red. The scheme is the following: Alice will puts her two cards ON TOP of the remaining red card: to say yes, she puts her black card on top of her red card, to say no she does the opposite (red on top of black). Bob will put his pair of cards BELOW the remaining red card, and to say yes he puts his black card at the bottom, with his red card in between, and to say no he does the opposite. Then you cut the deck enough times to obfuscate who've done what, and you know that they've both day yes if you have the two blacks cards next to each other (or both at each ends of the deck). If anyone (or both of them) said no, you'd have black cards separated by one red card. [1] https://fr.wikipedia.org/wiki/Jacques_Patarin https://fr.wikipedia.org/wiki/Jacques_Patarin
- wfh 4y agoReminds me a paper I co-authored all the way back in 2000! https://www.cl.cam.ac.uk/~fms27/papers/2000-StajanoHar-romantic.pdf https://www.cl.cam.ac.uk/~fms27/papers/2000-StajanoHar-roman... wow that's a long time ago!
- ok_dad 4y agoI might be an old timer but there used to be a site where you would put in your email and your crushes email and if they did the same you’d both be notified. I don’t remember the name of the site now though.
- Ankaios 4y agoHere's one: https://catalst.net/ https://catalst.net/
- ransom1538 4y agoWow that is evil genius.
- dylan604 4y agoallyourcreditarebelongtous.com? i assume at this point in life that any site doing something as silly as this has ulterior motives for the site's existence.
- jonahbenton 4y agoWhat if you love hashes?
- leto_ii 4y ago> People can enter their names into this unique link to generate the hash of their name. If the generated hash matches, they'll be notified *you* are *their* crush Don't mean to be pedantic, but shouldn't it be "they'll be notified *they* are *your* crush"?
- AndrewStephens 4y agoI used a similar technique to obfuscate the answers in a silly TV quiz[0] I wrote a couple of years ago. I have a terrible habit of looking at the source of web-based puzzles to discover the solutions and wanted to make something where that was impossible. My solution was to use the given answers as the key to decode a small blob of data. Multiple correct answers (different spellings) were handled by simply encoding the blob multiple times and trying them all. Everything happens client side but at no time does the client store any information about the answers unless the user proves they know them by typing them in. [0] https://sheep.horse/2020/4/tv_opening_sequences_quiz.html https://sheep.horse/2020/4/tv_opening_sequences_quiz.html
- samiur1204 4y agoLol, sending someone the link kind of defeats the purpose, no?
- baby 4y agoThis has nothing to do with zero-knowledge crypto. Here's some intuition about what zero-knowledge is actually about: https://minaprotocol.com/blog/kimchi-the-latest-update-to-minas-proof-system#But-first-what-is-a-proof-system https://minaprotocol.com/blog/kimchi-the-latest-update-to-mi...
- hinkley 4y agoIt's my understanding that zero-knowledge concepts can be extended to databases, in a way where I can query a database and get a result without knowing the contents, perhaps to pass on to a trusted system to perform another action. Depending how you slice it, I either do or don't get to know if the result set is empty. In the latter case, there's a variation of this crush registration system where I don't get to know if Sally has a crush on me, but I do find out if anyone has a crush on me. Of course if the answer is empty set, I don't know if I'm unloved or only loved by people that don't use the app. Which could be pretty heavy.
- rocqua 4y agoThis system is not zero knowledge, because publishing the link actually leaks info to non-intended recipients. Suppose I share a link, and you suspect I am trying to steal your partner. You could easily check whether my crush is your partner.
- baby 4y agoWhat you’re describing is more like MPC to me
- totetsu 4y agoCrypto like cryptography or crypto like cryptocurrency?
- boomboomsubban 4y agoAren't they the same? Cryptocurrency is called that because it uses cryptography.
- 4y ago
- paxys 4y agoNice. Kinda along the lines of what made the current generation of dating apps (starting with Tinder) so popular. Take a large group of 1st and 2nd degree friends. People anonymously select who all they'd like to get with. If there's a match, both parties are notified. If not, no one gets to know. It's such a simple concept, and it's odd that someone like Facebook wasn't able to capitalize on it first despite providing all the infrastructure (the social graph) to make a service like this possible in the first place.
- quickthrower2 4y agoFacebook knows enough about you to skip that step and just match you.
- makach 4y agoYeaaahh, but no. It doesn’t need to be mutual. Guess can be correct but the reveal will probably just out you and cause problems. For confessing your love do it openly, they are no short cuts.
- blueplanet200 4y agoThis is not the usual notion of zero-knowledge.
- mensetmanusman 4y agoThis is perfect for this generation.
- m3kw9 4y agoHow is this zero knowledge? It could have been a simple string equality on the back end.
- drog 4y agoThis protocol has some downsides - if you share the link with large adversarial group (e.g. your school) they can brute force your crush name and it’s basically no different then embarrassingly shouting out your crush name in public and it has problems with canonical names. Instead we can alter it and fix this problems: Bob will find out his crush’s public key, encrypt "you are my crush" message to it and post it with his own signature to public bulletin (blockchain can be good shelling point). When crush decrypts message they will see proper string, while everyone else will see gibberish. - to solve problems with key distribution we can use "identity based encryption". it requires trusted third party (e.g. school administrators) but it solves problem for key generation of participants. With identity encryption bob can encrypt message to some canonical identity such as school email. Owner of that email can prove it’s identity to the third party and receive corresponding private key.
- SirZimzim 4y agoThis guarantees the crush will never see their message.
- scubbo 4y ago> blockchain can be good shelling point I can absolutely guarantee that the school generation would not naturally gravitate to the blockchain as a source for social interaction, since it's not (yet) running social media. I'm assuming TikTok (if it's common to post your own videos and not just consume?) or Snapchat (or whatever came next, that's probably old enough to be uncool by now I guess?) EDIT: I just saw the suggestion that school administrators be identity providers for a crush-admission website. OK, now I'm _sure_ this must be satire. Well played.
- Godel_unicode 4y agoAnd then someone will guess that the school administrators password is “StudentsSucks2022” and steal all the private keys they left in their documents folder.
- drog 4y agoYou are correct, but I think "identity based encryption" protocols can run in MPC mode. Multiple parties will generate distributed secret that will be used to generate private keys. Anyone can easily generate public key for any identity (e.g. email) for the given "key generator" setup using public data of this setup. But for a user to get their private key, they need to assemble secrets by proving their identity to multiple independent parties - you have to hack every one of them to restore the private key of user.
- deleted 4y ago[deleted]
- webkike 4y agoWhat if someone has a list of possible crushes you may have? Social circles aren’t incredibly large
- productceo 4y agoFinally, a way to secretly confess my love for justice and world peace.
- dougk16 4y agoNice, quick implementation. It's cool that it's all client side. People have pointed out the weaknesses as far as non-crushes brute forcing the answer but still this is interesting. I'll have to digest the implications more. I created https://aytwit.com/thoughter https://aytwit.com/thoughter which takes the basic idea here to a much more involved extreme. It got some good traction on hackers news a few years ago and I've improved it a lot since then. I still want to make some improvements as far as moving more of the cryptography client-side so people don't have to trust my server as much, yet not ALL client side like this for more convenience and privacy. Thanks for the submission!
- outloudvi 4y agoWould a double SHA256 hash make it securer?
- YayaScript 4y agoVery nice! but it's not a zero-knowledge application at all
- rocqua 4y agoI found this blog post a great explanation: https://blog.cryptographyengineering.com/2014/11/27/zero-knowledge-proofs-illustrated-primer/ https://blog.cryptographyengineering.com/2014/11/27/zero-kno... The cave parable always confused me. This blog-post made it click. I think the 'secret passage in the cave' is just a very bad stand-in for knowledge. Perhaps a maze would be better. But the parable also focuses to much on 'creating false transcripts' without explaining why being able to fake it makes it 'zero knowledge'.