1995-10-24 - Re: How can e-cash, even on-line cleared, protect payee identity?

From: Jiri Baum <jirib@sweeney.cs.monash.edu.au>
To: hfinney@shell.portal.com (Hal)
Hello Hal <hfinney@shell.portal.com>
  and cypherpunks@toad.com

H wrote:
> "Simon Spero" <ses@tipper.oit.unc.edu>  wrote:

[about fully-anon ecash]
> There could be an issue of fraud, though,
> where Bob insists that Alice's coin was no good even though it actually
> was.

Cut'n'choose between Alice and Bob? Ie Alice asks Bob for half the blinds
to check that the proto-coins are true?

Apart from no-good proto-coins, is there any other way the coin
could be no good?

As for no-good proto-coins, it's Bob's fault, isn't it? Alice has 
a record of what Bob sent, and what she sent back. Anybody can check
that the latter is a bank-signed version of the former. Given this,
there's no need (from this) for Alice to know that the proto-coins are
good (if they aren't, Bob's an idiot, but there's not much Alice
can do about it - I guess given all the blinding factors the bank
could replace the coin, seeing that it signed a worthless one).

So Bob can't really fraud - unless I've missed something.

An interesting question is whether Bob and Nick can now collude to
expose Alice. Therefore Alice would at least want to verify that the
proto-coins are true? Would that suffice? Or is that not necessary?

> Still, I think this scheme has considerable merit and is worth exploring


Version: 2.6.2i