I've been around crypto long enough to hear the same privacy argument in different clothes: if you want convenience, you eventually have to give something up.
I keep thinking about Dusk's Phoenix design because it challenges that assumption in a pretty practical way.
Phoenix doesn't force the phone to do everything. Its viewing capability can be delegated so a third party can scan for your notes without getting the authority to spend them. ZK proof generation can also be pushed to an external prover. That changes the privacy-versus-usability argument for me. Privacy doesn't necessarily mean your phone has to carry all the computation.
But I've seen this movie before. Outsourcing a sensitive task doesn't remove trust. It moves it.
A delegated viewer may not be able to steal your funds, but it can still learn that you received money and potentially build a picture around your activity. The protocol can separate seeing from spending, but it can't make the party doing the seeing irrelevant.
That's where I'm cautious.
I like this because it doesn't pretend privacy is free. You can reduce the burden on your own device, but you may increase the exposure surface somewhere else.
Would I delegate viewing? Maybe for routine funds. For anything truly private, I'm not sure yet.
I've learned that the better question isn't just “Is this private?”
It's “Who am I trusting, and what exactly am I giving them?”
@Dusk_Foundation #dusk $DUSK
I keep thinking about Dusk's Phoenix design because it challenges that assumption in a pretty practical way.
Phoenix doesn't force the phone to do everything. Its viewing capability can be delegated so a third party can scan for your notes without getting the authority to spend them. ZK proof generation can also be pushed to an external prover. That changes the privacy-versus-usability argument for me. Privacy doesn't necessarily mean your phone has to carry all the computation.
But I've seen this movie before. Outsourcing a sensitive task doesn't remove trust. It moves it.
A delegated viewer may not be able to steal your funds, but it can still learn that you received money and potentially build a picture around your activity. The protocol can separate seeing from spending, but it can't make the party doing the seeing irrelevant.
That's where I'm cautious.
I like this because it doesn't pretend privacy is free. You can reduce the burden on your own device, but you may increase the exposure surface somewhere else.
Would I delegate viewing? Maybe for routine funds. For anything truly private, I'm not sure yet.
I've learned that the better question isn't just “Is this private?”
It's “Who am I trusting, and what exactly am I giving them?”
@Dusk_Foundation #dusk $DUSK