Comment by teravor
10 hours ago
combine with a central authority server network and make it blind signatures and you have untraceable e-cash.
10 hours ago
combine with a central authority server network and make it blind signatures and you have untraceable e-cash.
Blind signatures don’t work like that. Once you unblind them, they are very traceable. Chaumian e-cash can only be spent once for that reason.
when you unblind a blind signature all the signer knows is that it's a signature they signed at some point, they know nothing (true zero knowledge) about when or where they signed it among all the other signatures.
Yes, and then you have a signed piece of data that others can verify. How does that help you with preventing duplication of signatures?
E-cash depends on the secrecy of the signed data, and immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash.
No government wants untraceable e-cash. They want it fully traceable.
it would depend on the government and the situation. I suspect most don't realize this is possible. a small government can generate immediate demand for their currency doing this.
The original e-cash paper is from 1983. Governments absolutely know this is possible.
It's just much "too private" to get any political traction. At the very least, I suspect an acceptable modern alternative would either have caps on what can be sent/received completely anonymously (e.g. per recipient and timespan) or want non-anonymous recipients (to allow for VAT/sales tax accounting etc.)