9 ms·
sounds like you could have anonymous currency. heres our FHE bank. we both have accounts. the entire ledger is encrypted. i give you 5 dollars, i have no idea
by fatneckbeard 4y ago
sounds like you could have anonymous currency.
heres our FHE bank. we both have accounts. the entire ledger is encrypted.
i give you 5 dollars, i have no idea what your starting and ending balance, but i am still able to initiate a transaction that will deduct 5 from mine, and add 5 to yours, and verify i actually have 5 to send, and the entire thing will be done without exchange of information about balances with any outside party. its just approved/declined by the algorithm. i can see my own balance with my own key, you can see your own balance with your own key, but we cant see each others balance. ---nor could anyone else including the bank---.
weird. and kind of scary. and most definitely illegal in the real world since the bank itself could never prove its reserve level of deposit met the percentage set by government.
- CraigJPerry 4y ago>> since the bank itself could never prove its reserve level of deposit met the percentage set by government There’s no minimum reserve set by the fed anymore: https://www.federalreserve.gov/monetarypolicy/reservereq.htm https://www.federalreserve.gov/monetarypolicy/reservereq.htm
- aspyct 4y agoOther countries exist.
- eru 4y agoSee https://en.wikipedia.org/wiki/Reserve_requirement https://en.wikipedia.org/wiki/Reserve_requirement Many countries don't have a reserve requirement. The US was a bit of a laggard. Minimum reserve requirements were always a bit silly. You want your banks to have a thick capital cushion for its debt. Whether they have reserves on hand is an operational problem they can solve themselves, and doesn't have systemic consequences.
- PeterisP 4y agoIt's not really about the reserve requirements, but about basic accounting requirements, which all banks do have. At its fundamentals, bank balances are not some storage of "your money", they are recording of how much the bank legally owes you (or vice versa). And of course the bank has to know exactly what liabilities they have according to their contracts, so they need to see the balances. They also need to be able to add arbitrary quantities of new money to the FHE scheme when cash is paid in and remove it when it is paid out.
- piaste 4y agoOr, more succinctly, what makes a bank a bank is that it will loan out money deposited by other people. If the money is just sitting there and can't be moved or even counted without the owner's private key, it's not a bank, it's a vault.
- CraigJPerry 4y ago>> what makes a bank a bank is that it will loan out money deposited by other people No, a bank creates money to loan out from nothing. No deposits required. As a sibling comment points out, other jurisdictions exist so here's the UK central bank's explainer on the topic: https://www.bankofengland.co.uk/explainers/how-is-money-created https://www.bankofengland.co.uk/explainers/how-is-money-crea...
- fatneckbeard 4y agobut once the bank has made the loans, it has to keep track of how many it has made and how many are delinquent. i could be missing something.
- CraigJPerry 4y agoYeah of course, but that's not the point the parent was contesting. They claimed a bank loans from funds deposited which isn't the case. If a bank chooses to create an asset (your liability) by loaning money to you, if you then fail to repay, then they're in a bad spot. They're certainly not allowed to just delete the records of the loan being issued to get rid of the delinquent asset on their balance sheet.
- noduerme 4y agoI love/hate this. It's one of those ideas that's incredibly appealing to people who already have other ways of doing it, and incomprehensible to people who would actually benefit from it. Most things of that ilk get blown up because once it's peddled to the masses, consumers don't verify that it's actually run the way it's supposed to be run, and someone writes in a backdoor (FTX). Then it just takes a few hyped up claims and burst bubbles before it becomes a punchline. What would be sort of awesome, though, would be a distributed bank (or prediction market, or casino) along these lines. If every node can donate processing power to run totally encrypted transactions, it's a game changer. You could finally rely on client-side processing to deal poker hands and process game states without a central server, for example.
- 8n4vidtmkvmk 4y ago> You could finally rely on client-side processing to deal poker hands and process game states without a central server, for example. Interesting. I had given up on that idea. Not just for poker, but MMOs n stuff. Figured anything of importance had to run server-side.
- noduerme 4y agoit does. But if you could drop an encrypted VM on each client - where the instructions and responses were encrypted, and even frozen/dumped states were encrypted... you'd finally have no need for centralized game servers to arbitrate who sees which part of a hidden state. You could put every player's secrets, and the secrets of the game state, on each client and use their processing in parallel.
- heartbeats 4y ago> What would be sort of awesome, though, would be a distributed bank (or prediction market, or casino) along these lines I think this is already possible for poker, and will never be possible for prediction markets. Prediction markets require human resolution of "fuzzy" questions. For example, who won the 2020 US presidential election? You can see why the limiting factor isn't the machine. But for poker, why do you need FHE? To play poker, you have to deal two hole cards and five community cards. First each player gets two secret ("hole") cards, then three community cards are dealt ("flop"), then potentially another ("turn"), then potentially another ("river"). This could be done programmatically as such: 1. Each player generates five secrets: k_HOLE, HOLE, FLOP, TURN, RIVER 2. Each player derives public key K_HOLE from k_HOLE. 3. Each player publishes the hash of each secret in addition to K_HOLE. 4. Each player publishes their value of HOLE, which is checked against the hash from previous step. 5. To get the two hole cards for you, calculate H(HOLE_1 || HOLE_2 || ... || HOLE_N), decrypt the resulting value using k_HOLE (secret to you), then deterministically turn this into cards (for example: hash it, then map the first half into 52 values and the second half into 51 values) 6. Once it's time for the flop, all players publish FLOP. Then calculate H(FLOP_1 || FLOP_2 || ... || FLOP_N). 7. Repeat for turn and river as necessary. The only difficult part is how to handle colors, but I don't think this is a serious issue, since nobody counts cards in poker anyway. (We can trivially ensure flop, turn and river don't repeat cards, so it's just a question for the hole cards vis-a-vis the community cards) EDIT: Looks like someone has already tried to do this seven years ago: https://github.com/zweicoder/PokerPhase https://github.com/zweicoder/PokerPhase
- vintermann 4y agoSure. And then, after you've transferred 5 dollars to me, I say "What 5 dollars? What are you talking about?" and refuse to hand over the thing that you thought you bought. Add perfect anonymity to the mix and I get to do it over and over again, too.
- 3np 4y agoYou could still design the scheme such that the sender can produce a cryptographic proof. Equally applicable for tax auditing etc.
- macrolime 4y agoYou could set it up so whoever initiates a transfer could get a kind of receipt that proves they initiated a transfer of X dollars to whomever. So if Alice transfers 5 dollars to Bob and Bob says "What 5 dollars? What are you talking about?", then Alice could say, well here's my receipt, that's signed by my private key and the private key of the FHE bank, that shows that I sent the money to Bob and the FHE bank executed the transfer.
- ricksunscreen 4y agoYou get this for free with FHE. In the event of a dispute, you can reveal the randomness and message that produce the public ciphertext given the user's public key.
- deleted 4y ago[deleted]
- 3np 4y agoYou don't need FHE for that. It's possible through some zero-knowledge schemes, such as zk-SNARKS, which is implemented in and popularized by shielded transactions on Zcash.
- easrng 4y agoYou don't need zk-SNARKS for that. It's possible through some schemes, such as blind signatures, which have been successfully implemented many times but their usage for currency has (iirc) proved legally problematic.
- rattlesnakedave 4y agoFor the uninitiated: https://sceweb.sce.uhcl.edu/yang/teaching/csci5234WebSecurityFall2011/Chaum-blind-signatures.PDF https://sceweb.sce.uhcl.edu/yang/teaching/csci5234WebSecurit... Chaumian mints are gaining some popularity in the bitcoin world: https://fedimint.org/ https://fedimint.org/
- 3np 4y agoSure, and apparently there's a coin for that too, by Chaum himself[0] :P (If it's not obvious: Blind signature as such are solid but I wouldn't suggest anyone to give a cent to this sketchy project) AFAIK (and I'd be thrilled to be proved wrong) we still haven't figured out how to solve double-spend using blind signatures without a blockchain and so the schemes I've seen so far invariably involve either that or a trusted mint and are therefore less interesting to use as currency. Assuming you already have a base digital currency (like bitcoin), they can still be interesting on/as a higher layer. [0]: https://xx.network/blog/decrypt-how-david-chaum-went-from-inventing-digital-cash-to-pioneering-digital-privacy/ https://xx.network/blog/decrypt-how-david-chaum-went-from-in...
- mik1998 4y agoGNU Taler does something similar, except without homomorphic encryption. It only anonymizes the payer however.
- esperent 4y agoWhat purpose would this serve? Just anonymity for the sake of anonymity, or something else?
- esperent 4y agoNote: this was a genuine question, with genuine interest in the answer. Why the downvotes?
- noduerme 4y agoSeems a fair question. In a private banking context, it would potentially eliminate the need to pay escrow fees to a third party, without resorting to massively inefficient public ledgers. In the context of e.g. stock trading, it might mean that a traditional bank can connect buyers and sellers over a peer to peer connection and guarantee that their trades execute in order without even needing a centralized book. That's maybe a slightly extreme take, and probably a ways off. But I think anonymity is the least important of what becomes available if you can trust client-side processing.
- fatneckbeard 4y agoits basically a thought experiment. one of the things i never understood about bitcoin was the idea of the public ledger. one of the main things about most people and businesses in general is that they do not want to draw attention to their actual flows of money. the idea everyone would want their entire purchase and payment history "out there" in public never made sense to me. but if you could actually make bitcoin anonymous, then what would happen? would it be adopted more? or would the government actually have to crack down?