Ok I'm not sure about "image key". I red somewhere it is derived from private key (so only me can verify because only I know private ) ... But in this paper "image key" is derived from pubic key. Does it mean I can use VER to find out who is really spending ?
This is a TA thread - if you're struggling to grasp the cryptography then you are welcome to continue this discussion in the Monero ANN thread:
https://bitcointalk.org/index.php?topic=583449.0Alternatively, if you believe you've found an exploit, I do encourage you (again) to document it and write a PoC like every other security researcher. The process of writing a PoC normally forces me to come to grips with the intricacies of the subject, and I document thereafter.
Rem tene verba sequentur, as they used to say.
Is that "image key" public observable ? Every node knows what input is really spent and who ring-sing this message ?
If I know YOUR public key, from an unspet input . You are broadcasting new transaction (is not yet minted). I can compute "image key" and create ring singature of YOUR input with my privateKey ... and output to my address. What transaction will win ?