← Back to context

Comment by teravor

10 hours ago

combine with a central authority server network and make it blind signatures and you have untraceable e-cash.

Blind signatures don’t work like that. Once you unblind them, they are very traceable. Chaumian e-cash can only be spent once for that reason.

  • when you unblind a blind signature all the signer knows is that it's a signature they signed at some point, they know nothing (true zero knowledge) about when or where they signed it among all the other signatures.

    • Yes, and then you have a signed piece of data that others can verify. How does that help you with preventing duplication of signatures?

      E-cash depends on the secrecy of the signed data, and immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash.

No government wants untraceable e-cash. They want it fully traceable.

  • it would depend on the government and the situation. I suspect most don't realize this is possible. a small government can generate immediate demand for their currency doing this.

    • The original e-cash paper is from 1983. Governments absolutely know this is possible.

      It's just much "too private" to get any political traction. At the very least, I suspect an acceptable modern alternative would either have caps on what can be sent/received completely anonymously (e.g. per recipient and timespan) or want non-anonymous recipients (to allow for VAT/sales tax accounting etc.)