Optimistic about judicious uses of tech. Systems, security, privacy, cryptography, and the web are my jam.
Previously: Clever, Square, Mozilla, Harvard, MIT.
Accuracy of the count, however, isn't affected even if all trustees collude.
Accuracy of the count, however, isn't affected even if all trustees collude.
Best I can think of right now without actual threshold cryptography would be escrowing your share encrypted against one other trustee's public key.
Best I can think of right now without actual threshold cryptography would be escrowing your share encrypted against one other trustee's public key.
IACR is going to move to 2-out-of-3 manually for now by sharing a key share across two trustees.
And then I gotta think about how to make this better, whether there is a reasonable UX.
IACR is going to move to 2-out-of-3 manually for now by sharing a key share across two trustees.
And then I gotta think about how to make this better, whether there is a reasonable UX.
All I can say is, if you're making fun of someone who lost their secret key, you're doing it wrong. It will happen to you someday, too.
And I need to make Helios better.
All I can say is, if you're making fun of someone who lost their secret key, you're doing it wrong. It will happen to you someday, too.
And I need to make Helios better.
So I made the trustee function really scary. By default, Helios manages the key, and privacy is not as strong. There's an ugly scary popup if you try to set up trustees.
So I made the trustee function really scary. By default, Helios manages the key, and privacy is not as strong. There's an ugly scary popup if you try to set up trustees.
For resilience, it seems clear you should tolerate some trustees being absent. But that complicates the setup process: all trustees need to log in once, then a second time.
For resilience, it seems clear you should tolerate some trustees being absent. But that complicates the setup process: all trustees need to log in once, then a second time.
But there's a very specific design tradeoff here.
But there's a very specific design tradeoff here.