You're looking at Less Wrong's discussion board. This includes all posts, including those that haven't been promoted to the front page yet. For more information, see About Less Wrong.

paulfchristiano comments on Homomorphic encryption and Bitcoin - Less Wrong Discussion

5 Post author: jimrandomh 19 May 2011 01:07AM

You are viewing a comment permalink. View the original post to see all comments and the full post content.

Comments (9)

You are viewing a single comment's thread. Show more comments above.

Comment author: paulfchristiano 19 May 2011 02:52:53AM 5 points [-]

I see. My earlier proposal defends you against an adversary who steals your computer, but not against one who has root access without your knowledge.

In that case it is sufficient to have secure function evaluation. This is conceptually much easier than homomorphic encryption (having been discovered some 25 years earlier) and is currently much more practical (ie, practical at all). I don't know much about existing implementations.