3 ms·
PAKE has been using ZKPs for a decade. Here. Read this : https://en.wikipedia.org/wiki/Password_Authenticated_Key_Exchange_by_Juggling https://en.wikipedia.org/
by nojokepoke 2mo ago
PAKE has been using ZKPs for a decade. Here. Read this : https://en.wikipedia.org/wiki/Password_Authenticated_Key_Exchange_by_Juggling https://en.wikipedia.org/wiki/Password_Authenticated_Key_Exc...
Funny that not only are you ignorant you are violently confident in your ignorance. I suffer from this sometimes too so I get it. Get some help.
- diamondclouds 2mo ago> Alice sends out It relies on trusting that Alice’s request is valid. If Alice sends another proof, she will have a different balance. Alice decides what to send. The server blindly accepts it. You actually don’t want that for a lot of security and that’s why nobody uses ZKP for passwords or really anywhere outside theory - dumb theory that doesn’t understand basic web dev. We already have hashing and databases. There is a narrow use case for trusting clients - like receiving updates from intranet or p2p devices - maybe you use ZKP to omit unnecessary pii. But that’s it. It’s not what you think it is.
- Groxx 2mo ago> Alice sends out Alice can send anything in any cryptographic scheme involving two parties, the only real safety in any of it is "are the odds of an accepted different value low enough to be impractical for an attacker". Does that apply here too?
- rubyclouds 2mo agoWhat? Of course it’s a massive security flaw if you let any end user device send anything they want and just go “well they probably won’t send fake amounts” Imagine such a bank. Or social media (impersonate anyone, just say you’re them on the request why not), or any website. The “zero knowledge” part of the name checks out.
- nojokepoke 2mo agoPlease explain how Alice’s request can ever be not valid. It’s literally a pre authenticated exchange. Also nice sock puppet.
- rubyclouds 2mo ago[dead]