Noticed that Dusk lists privacy and access controls as separate things and I had been treating them as one.
They are not the same problem.
Privacy answers who can see. Access control answers who can act.
You can have either without the other and both failures are real. A fully private chain where anyone can hold any asset fails a regulated securities requirement completely. A fully transparent chain with strict eligibility rules protects nothing about the holder.
Regulated assets need both at once and they need them to be independent settings. Some information should be confidential from the public but visible to a supervisor. Some actions should be permitted for one holder and blocked for another regardless of what anyone can see....
Uhm and I think this is why so much crypto privacy work never found a regulated use. It solved visibility and left permission entirely alone.
The caveat is that separating them also doubles what has to be configured correctly. Two independent systems means two places to get it wrong.
do you think of privacy and permission as one problem or two
@Dusk #dusk $DUSK