Last night I reopened some old code, sat watching the terminal run proof after proof and forgot about my coffee... thought of @Dusk.
when I read SBA Consensus, I was more drawn to Blind Bid, Proof-of-Blind Bid and Private Leader Election than Privacy.
Block Generator participates in Non-interactive Sortition, Confidential bid sits behind Zero-Knowledge Proof.
No Signaling.
No Targeting.
No Stake-Based Surveillance.
but honestly, after debugging it myself a few times, I am no longer easily convinced by the word “private”...
I look at Prover, Verifier, Circuit Constraints, Polynomial Evaluation and dusk-plonk.
suppose 1,000 proofs go through, each proof has 4 Polynomial Evaluations that need to be checked, meaning 4,000 verification points.
what if a Verification Gap sits exactly where the most important Security Assumption is?
Malicious Prover does not need to break the entire system.
it only needs a gap small enough for a Forged Proof to slip through, then BlindBidProof, Sortition Correctness and Consensus Security start becoming a different story.
that is what I fear most about Cryptographic Implementation: Attack Surface is sometimes not broad...
MEV Resistance is genuinely strong.
Targeted-Attack Resistance is worth a lot too.
but the more a Privacy Layer hides from the user's eyes, the more I demand Battle Testing to be brutal, the tougher the Verifier has to be, Verification Correctness has to become almost obsessive.
OtterSec once hit exactly on unchecked Polynomial Evaluations, and that made me change the way I see it: a protocol is not trustworthy because it uses PLONK, but because the assumptions underneath PLONK have been hammered on for long enough and are still standing.
I still like the direction DUSK is taking... it is just that now I no longer ask “how much privacy do we get”.
I ask: how many punches has the part we cannot see already taken?
if you had to choose, would you trust a system because its design is the most beautiful, or because its Verifier has survived the worst tests?
#dusk $DUSK @Dusk
when I read SBA Consensus, I was more drawn to Blind Bid, Proof-of-Blind Bid and Private Leader Election than Privacy.
Block Generator participates in Non-interactive Sortition, Confidential bid sits behind Zero-Knowledge Proof.
No Signaling.
No Targeting.
No Stake-Based Surveillance.
but honestly, after debugging it myself a few times, I am no longer easily convinced by the word “private”...
I look at Prover, Verifier, Circuit Constraints, Polynomial Evaluation and dusk-plonk.
suppose 1,000 proofs go through, each proof has 4 Polynomial Evaluations that need to be checked, meaning 4,000 verification points.
what if a Verification Gap sits exactly where the most important Security Assumption is?
Malicious Prover does not need to break the entire system.
it only needs a gap small enough for a Forged Proof to slip through, then BlindBidProof, Sortition Correctness and Consensus Security start becoming a different story.
that is what I fear most about Cryptographic Implementation: Attack Surface is sometimes not broad...
MEV Resistance is genuinely strong.
Targeted-Attack Resistance is worth a lot too.
but the more a Privacy Layer hides from the user's eyes, the more I demand Battle Testing to be brutal, the tougher the Verifier has to be, Verification Correctness has to become almost obsessive.
OtterSec once hit exactly on unchecked Polynomial Evaluations, and that made me change the way I see it: a protocol is not trustworthy because it uses PLONK, but because the assumptions underneath PLONK have been hammered on for long enough and are still standing.
I still like the direction DUSK is taking... it is just that now I no longer ask “how much privacy do we get”.
I ask: how many punches has the part we cannot see already taken?
if you had to choose, would you trust a system because its design is the most beautiful, or because its Verifier has survived the worst tests?
#dusk $DUSK @Dusk