Commit 3915f27
committed
Add a known-limitations section to the draft spec as honest disclosure
New top-level section collecting what is unproven or structurally weak: no
formal proof of the composite (including KB21's non-adaptive soundness model),
knowledge-based holder binding via the link secret (exfiltration and lending
limits, hardware anchoring as deployment choice), adaptive predicate bounds
enabling binary search of hidden values, silent key compromise (issuer key,
alphabet x, registry alpha, plus Cheon-style u-SDH degradation), no side-channel
hardening, post-quantum status, and the boundary of cryptographic unlinkability
(disclosed-value and request-shape fingerprinting, bbs-2023 schema leak, issuer
anonymity-set cap). Also adds two security/privacy considerations: presentations
as transferable issuer-endorsed evidence, and registry feed equivocation as the
accumulator analog of per-prover alphabets. Regenerates the committed HTML.1 parent b9a5691 commit 3915f27
2 files changed
Lines changed: 373 additions & 50 deletions
0 commit comments