Post
Topic
Board Speculation
Re: Gold collapsing. Bitcoin UP.
by
TPTB_need_war
on 09/06/2015, 10:12:17 UTC
In any case, the concept is sort of inane. Who ever receives a payment can trace all the way back through the chain of payment history of obscured amounts. So afaics the anonymity breaks down over time to eventually 0. Please correct me if I am mistaken.

I think I conflated with the "respendable commited-tx". The homomorphic encryption was 5 slides above that. So perhaps the HE does not have the flaw I assumed. So it hides payment amounts but doesn't mix outputs from numerous entities. You'd still need CoinJoin for that, which is unscalable. And if you add on-chain ring sigs, then you don't need the HE. Also I don't understand how hiding the amount helps when the amount needs to be same for all those who are mixing in CoinJoin  Huh (otherwise analysis of permutations between input and output amounts can decrease the anonymity set).

So far this looks like another one of those half-baked Gregory Maxwell ideas.  Roll Eyes I await clarification.

Links:

https://bitcointalk.org/index.php?topic=509674.0
https://bitcointalk.org/index.php?topic=305791.0