#dusk $DUSK Phoenix Viewing Keys: The Quiet Privacy Risk
I keep coming back to one uncomfortable detail in Dusk’s Phoenix design: a viewing key looks harmless until I stop thinking about it as simple “view access.”
I can imagine the legitimate workflow. An issuer authorizes an auditor to inspect a Phoenix transfer, verify amounts, reconcile counterparties, and complete a report. The transfer is settled. The notes remain shielded from everyone else. Selective disclosure works exactly as intended.
But I see a different problem after the report ends.
The audit has a lifecycle. The viewing authority might not.
I can revoke a key later, but I cannot revoke information that already reached the auditor’s systems. Once Phoenix data is exported into reconciliation files, reports, or internal records, changing permissions does not pull that information back into the shielded state.
That creates the question I think matters most:
Who still has Phoenix viewing authority after the original reason for access disappears?
DuskDS finality can settle the transaction. Phoenix can preserve confidentiality. But privacy also depends on controlling the lifespan of disclosure itself.
That is where the real infrastructure question begins.
@Dusk_Foundation
I keep coming back to one uncomfortable detail in Dusk’s Phoenix design: a viewing key looks harmless until I stop thinking about it as simple “view access.”
I can imagine the legitimate workflow. An issuer authorizes an auditor to inspect a Phoenix transfer, verify amounts, reconcile counterparties, and complete a report. The transfer is settled. The notes remain shielded from everyone else. Selective disclosure works exactly as intended.
But I see a different problem after the report ends.
The audit has a lifecycle. The viewing authority might not.
I can revoke a key later, but I cannot revoke information that already reached the auditor’s systems. Once Phoenix data is exported into reconciliation files, reports, or internal records, changing permissions does not pull that information back into the shielded state.
That creates the question I think matters most:
Who still has Phoenix viewing authority after the original reason for access disappears?
DuskDS finality can settle the transaction. Phoenix can preserve confidentiality. But privacy also depends on controlling the lifespan of disclosure itself.
That is where the real infrastructure question begins.
@Dusk_Foundation