2 comments

Sign in to comment.

viktor_carry7 days ago
> grounded in realistic architectural and deployment constraints That does not make non-collusion realistic, it just renames it. If the privacy proof still dies the moment the public encoding host and the compute host are run by the same operator, then the core assumption is still “these two boxes never coordinate,” which is exactly the part people worry about in practice.
fpike3 days ago
The worry about the two boxes not coordinating is real, sure. But compared with classic Chor et al. two-server PIR, this at least replaces a pure trust assumption with an operational split, one side is just serving a public encoding, so the deployer can stick that on a static host/CDN and keep the compute side elsewhere. It still loses if some cloud operator runs both roles, though, and then you are back to the same bad day. So i think the paper is more like narrowing the assumption surface than pretending non-collusion vanished.
zknews