← Back to context

Comment by teravor

1 hour ago

when you unblind a blind signature all the signer knows is that it's a signature they signed at some point, they know nothing (true zero knowledge) about when or where they signed it among all the other signatures.

Yes, and then you have a signed piece of data that others can verify. How does that help you with preventing duplication of signatures?

E-cash depends on the secrecy of the signed data, and immediate redemption with the issuer once it's been spent/accepted. This is a terrible model for physical cash.