2 ms·
The sentence is a little unclear, but it is a little clearer if you consider things from the perspective of an organized attacker who controls some number of pa
by ezyang 14y ago
The sentence is a little unclear, but it is a little clearer if you consider things from the perspective of an organized attacker who controls some number of parties in the transaction. Even if the attacker messes around with the addresses of his keys, he doesn't learn anything about the addresses of the other participants: he can control the order of their keys relative to his, but not the relative order of keys among themselves.
- yafujifide 14y agoRight. If you think you're dealing with 100 people, but it's actually 1 person with 100 addresses, then they can determine which output address is yours because it is the only one that isn't theirs.
- ezyang 14y agoCorrect, the usual problems with Sybil attacks still apply: the point is that the attacker doesn't gain anything from faking addresses.
- Natsu 14y agoSo can you counter that by having everyone make multiple addresses explicitly (and only using some of them)? Then you could have everyone ante 1/16th bitcoin or whatever minimum is sensible and dispense with the power of two thing, because everybody would have hundreds of wallets in the transaction. Or does that just create a lot of correlations when those coins get consolidated?