On 8 March 2014 17:10, Alan Reiner wrote: > I create a new keypair, with which I know (it can be any > arbitrary key pair). But I don't give you , I give you = > minus (which I can do because I've seen before > doing this). > > Sure, I don't know the private key for , but it doesn't matter... > because what > > + = (mine) > > You have no way to detect this condition, because you don't know what > c_pub/c_priv I created, so you can only detect this after it's too late > (after I abuse the private key) > Thanks Alan and Forrest, that makes sense. So to salvage the situation in the original case, we have to make sure the parties exchange their public keys first, before they're allowed to see the public keys they'll be combining them with. -- -- Edmund Edgar Founder, Social Minds Inc (KK) Twitter: @edmundedgar Linked In: edmundedgar Skype: edmundedgar http://www.socialminds.jp Reality Keys @realitykeys ed@realitykeys.com https://www.realitykeys.com