At first I assumed Dusk’s committee security was mostly about how often participants are reshuffled. But the more I looked, the more the timing assumption stood out. The whitepaper keeps the Generator and Provisioner sets unchanged throughout an epoch, while assuming an adversary needs more than an epoch to corrupt a participant after selecting them as a target. That means the security model quietly depends on two clocks moving at different speeds: the committee rotation and the attacker’s ability to adapt. I find that more interesting than the randomness itself. A committee can stay in place for multiple rounds, but the assumption is that an attacker cannot react quickly enough to take advantage of that continuity. So the system is not only asking whether the right participants were selected. It is also relying on when those participants can realistically become compromised. Maybe that is simply the trade-off behind keeping committees stable for an epoch. Which leaves the quieter question: when does committee stability stop helping coordination and start giving an adaptive attacker more time?
#dusk $DUSK @Dusk
#dusk $DUSK @Dusk
