← Back to context

Comment by lxgr

9 hours ago

Blind signatures don’t work like that. Once you unblind them, they are very traceable. Chaumian e-cash can only be spent once for that reason.

when you unblind a blind signature all the signer knows is that it's a signature they signed at some point, they know nothing (true zero knowledge) about when or where they signed it among all the other signatures.

  • Yes, and then you have a signed piece of data that others can verify. How does that help you with preventing duplication of signatures?

    E-cash depends on the secrecy of the signed data, and immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash.

    •     > immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash
      
      

      not when everything is now online.

      also the obvious way such cash would work is that "redemption" is just the new minting of coin. the central authority will mint a new coin by blindly signing your secret after you "destroy" the spent coin by giving them the unblinded signature.

      1 reply →