[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

No Subject



Yes, I remember that now.  My interpretation, though, was that with the
bank's help you could tell when a coin had been re-used.  This could
impair the anonymity of the cash.  Generally in the analysis of these proto-
cols one wants anonymity even if the bank and the other participants
collude.  That is the whole point of cryptographic (non-transferable) cash,
after all; otherwise the bank could just use the "Poor Man's Cash" idea
which Tim May suggested here last year and just issue cash in the form
of magic numbers with no blinding or digital sigs.

Hal