<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wikidot="http://www.wikidot.com/rss-namespace">

	<channel>
		<title>Course Forum, Spring 2019 (new threads)</title>
		<link>http://blockchains-tau-s19.wikidot.com/forum/c-5870787/course-forum-spring-2019</link>
		<description>Threads in the forum category &quot;Course Forum, Spring 2019&quot;</description>
				<copyright></copyright>
		<lastBuildDate>Fri, 15 May 2026 01:57:11 +0000</lastBuildDate>
		
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12152392</guid>
				<title>HW 5</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12152392/hw-5</link>
				<description></description>
				<pubDate>Thu, 27 Jun 2019 11:23:19 +0000</pubDate>
				<wikidot:authorName>daniel</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi, can you please give us an answer sketch for HW 5 Q2 section b, and for Q3 section a?<br /> I asked around and I don't think anyone got full points for this.</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12142908</guid>
				<title>NIZK</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12142908/nizk</link>
				<description></description>
				<pubDate>Tue, 25 Jun 2019 15:16:45 +0000</pubDate>
				<wikidot:authorName>daniel</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>I have some questions regarding lecture 10 and NIZK.<br /> 1. We proved that the Hamiltonicity protocl is HVZK, and it is mentioned on the first page that it is not hard to show that it is also malicious verifier ZK.</p> <p>Corollary 4.3 states that If there exists a hash function H such that the Fiat-Shamir transform of, say, the Hamiltonicity protocol sound, the Hamiltonicity protocol cannot be ZK against malicious verifiers<br /> and then you say that Fiat-Shamir hash functions are believed to exist.</p> <p>So I don't understsnd how is this possible?</p> <p>2. I'm not sure I understand claim 4.1, from the claim &quot;make the verifier accept with probability at most (Q + 1)s&quot;<br /> Do you actually mean &quot;make the verifier accept with probability at most (Q + 1)s for x not in L&quot;<br /> because if x is in L we want to make the verifier exist with probability 1, right?</p> <p>Thanks.</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12123101</guid>
				<title>Example Exam 2b</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12123101/example-exam-2b</link>
				<description></description>
				<pubDate>Sat, 22 Jun 2019 14:41:20 +0000</pubDate>
				<wikidot:authorName>Nitzan P</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi</p> <p>Q2b seems inconsistent. If the puzzle is defined by <span class="math-inline">$y=x'-H(x') (mod N)$</span>, then where did the <span class="math-inline">$H(x+y)$</span> come from in the next line?</p> <p>Thanks</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12123003</guid>
				<title>Example Exam 1a</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12123003/example-exam-1a</link>
				<description></description>
				<pubDate>Sat, 22 Jun 2019 14:11:41 +0000</pubDate>
				<wikidot:authorName>Nitzan P</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi</p> <p>Can you be more formal? It is unclear what properties does this n-&gt;n-1 function has? Is n a predetermined parameter or we have such a function for any n? What does arbitrary compression means? (n-&gt;1 probably not so good) etc.<br /> Also the definition from class about collision resistant hashes was about function families and not single functions. Shouldn't the question be formulated using that notation?</p> <p>Thanks</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12070244</guid>
				<title>HW5 question 2</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12070244/hw5-question-2</link>
				<description></description>
				<pubDate>Tue, 11 Jun 2019 20:56:44 +0000</pubDate>
				<wikidot:authorName>Gal</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi,</p> <p>1) I'm a bit confused with the terminology. When an attacker joins <strong>before</strong> round r, is it possible that he already knows N(r) (with probability of atleast 99%) by the time he joins? For example, can we assume that if he publishes his pk just before the beginning of round r, with probability of atleast 99%, no more than m new nodes join after him before round r (where m is constant)?<br /> 2) In section b, is the leader chosen according to the original Algorand's consensus, or does the condition change for the leader as well?<br /> 3) Also in section b. What does &quot;takes control of the entire system&quot; mean? Does it mean that the attacker is able to control who becomes leader and which nodes will be on the committee for all future rounds? Does it have to be with probability 1?</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12067957</guid>
				<title>HW5 Q2</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12067957/hw5-q2</link>
				<description></description>
				<pubDate>Tue, 11 Jun 2019 09:39:37 +0000</pubDate>
				<wikidot:authorName>Guy Oren</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi,</p> <p>I am trying to parse the sentence: &quot;at the beginning of round r there are N(r) nodes in the system, each with equal stake&quot;.<br /> When new party join the system (and therefore create new node), what is the stake of that party? is N(r) does not change?</p> <p>Thanks,<br /> Guy Oren</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12060059</guid>
				<title>HW 5 Q3 b</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12060059/hw-5-q3-b</link>
				<description></description>
				<pubDate>Sun, 09 Jun 2019 20:07:57 +0000</pubDate>
				<wikidot:authorName>daniel</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>In Q3&#160;b, it is stated that in zerocoin the size of the proof statement to be proven scales with all zerocoins ever created.<br /> If I understand correctly then the reason is from lec 9 slides slide 32: &quot;Create zero-knowledge proof that: “You know a string r such that C=H(S, r) is one of the zerocoins &quot;C&quot; _1,…,&quot;C&quot; _𝑁 in the block chain”<br /> i.e. all the coins are part of the statement.</p> <p>Why do we need the coins to be part of the statement? the coins C_1,.. C_N are public and on the chain itself, so anyone can read them, why don't you generate a proof for the statement: “You know a string r such that C=H(S, r) is one of the zerocoins in the block chain&quot;</p> <p>Thanks</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12060043</guid>
				<title>recitation 9</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12060043/recitation-9</link>
				<description></description>
				<pubDate>Sun, 09 Jun 2019 20:04:01 +0000</pubDate>
				<wikidot:authorName>daniel</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>In recitation 9 we saw that if phi(N) = K*e, then the mapping x-&gt;x^e mod N is e to 1 by explicitly showing e elements.<br /> Did we also saw that these elements are indeed distinct? and if we did then how?<br /> i.e, how do you show that x^e != x^(k+1) mod N</p> <p>If I remember correctly, then I remember saying something about x^k != 1 mod N, but I don't think this is necessarily true.</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12056827</guid>
				<title>HW5 Q3a</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12056827/hw5-q3a</link>
				<description></description>
				<pubDate>Sun, 09 Jun 2019 06:24:20 +0000</pubDate>
				<wikidot:authorName>Etay Livne</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>In q3a it is not entirely clear what the scenario is. Node pk recieves a zerocoin, which he can then legitimately use to pay other nodes. What exactly is the attack pk is attempting to perform?</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-12002507</guid>
				<title>HW4 Q1C</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-12002507/hw4-q1c</link>
				<description></description>
				<pubDate>Fri, 31 May 2019 17:12:57 +0000</pubDate>
				<wikidot:authorName>daniel</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>are there any constraints on the prover?<br /> can he use more then O(n) time and polylog(n) space in the initialization phase?</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11980219</guid>
				<title>HW4 Q1C</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11980219/hw4-q1c</link>
				<description></description>
				<pubDate>Tue, 28 May 2019 15:49:47 +0000</pubDate>
				<wikidot:authorName>matan matzliach</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hey,<br /> I have 2 questions:<br /> 1. Is the prover limited to only sending the label of the node we are trying to verify or can it send more data?<br /> 2. In the initializtion phase, does the verifier still has access to the labels of all the nodes?<br /> Thanks.</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11977033</guid>
				<title>HW4 Q1A</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11977033/hw4-q1a</link>
				<description></description>
				<pubDate>Tue, 28 May 2019 08:28:29 +0000</pubDate>
				<wikidot:authorName>Guy</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi,</p> <p>I have question regard to the property of the diameter. the graph should have n nodes with diameter n, which by definition says that there is shortest path between 2 nodes that should traverse all nodes.<br /> such a path is not (d,r)-robust (i mean that if its the only path in the graph). so, in order to make the graph (d,r)-robust we should introduce &quot;short-cuts&quot;, but those short-cuts make the diameter of the<br /> graph smaller than n&#8230;</p> <p>so, it seems to me that this 2 requirements contradicts each other.</p> <p>its ok to say that i am wrong, and ask me to rethink about it :)</p> <p>Thanks,<br /> Guy</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11956946</guid>
				<title>HW4 Q1C</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11956946/hw4-q1c</link>
				<description></description>
				<pubDate>Sat, 25 May 2019 08:25:18 +0000</pubDate>
				<wikidot:authorName>michael</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Can we assume that the suggested candidate's graph is (d,r)-depth-robust?</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11951404</guid>
				<title>HW4 Q1A</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11951404/hw4-q1a</link>
				<description></description>
				<pubDate>Fri, 24 May 2019 07:21:55 +0000</pubDate>
				<wikidot:authorName>matan matzliach</wikidot:authorName>				<wikidot:authorUserId>5278232</wikidot:authorUserId>				<content:encoded>
					<![CDATA[
						 <p>Hey,</p> <p>In the question, we are asked to describe a (d,r)-depth-robust graph with n nodes with diameter n.<br /> Does it mean that we need to describe a specific graph that answers this condition, or any graph that answers it.</p> <p>In addition, I would like to know if the O(rlog(n)) space that the prover uses, could be set at the initialization phase, where we have access to all the labels,<br /> and for each verifier query use this data+ d oracle H calls.</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11576686</guid>
				<title>HW3 Q3</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11576686/hw3-q3</link>
				<description></description>
				<pubDate>Mon, 06 May 2019 09:29:35 +0000</pubDate>
				<wikidot:authorName>Guy Oren</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi,</p> <p>If we have 2 pools with the same power (alpha), does it mean alpha is 0.5?</p> <p>Thanks,<br /> Guy Oren</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11548522</guid>
				<title>HW3 Q3</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11548522/hw3-q3</link>
				<description></description>
				<pubDate>Sat, 04 May 2019 18:43:59 +0000</pubDate>
				<wikidot:authorName>Nitzan Pomerantz</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Hi,<br /> Regarding Q3 about Mining Pool Sabotage<br /> According to the recitation, specifically in the <span class="math-inline">$Gain_\beta$</span> statement it seems like the <span class="math-inline">$\beta$</span> power dedicated to sabotaging is just wasted. But what happens if P_1 finds a block from this mining power?<br /> Thanks</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11457491</guid>
				<title>HW3Q5</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11457491/hw3q5</link>
				<description></description>
				<pubDate>Mon, 29 Apr 2019 11:22:52 +0000</pubDate>
				<wikidot:authorName>Shahar Segal</wikidot:authorName>				<wikidot:authorUserId>2575668</wikidot:authorUserId>				<content:encoded>
					<![CDATA[
						 <p>&quot;We say ch and ch' are consistent if they agree on all but their last n blocks&quot;.<br /> If ch and ch' are of different size, what do we mean by last n blocks?<br /> Is n fixed for the entire protocol?</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11267403</guid>
				<title>HW 3 Q 2</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11267403/hw-3-q-2</link>
				<description></description>
				<pubDate>Sat, 20 Apr 2019 12:01:01 +0000</pubDate>
				<wikidot:authorName>daniel</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>In hw 3 q2, it is stated that for sanity check, for both a=0 and a=1 the result should be 2.<br /> but I don't understand it, if a=1 then the attack will end after 1 turn because it is guaranteed that the attacker will create the next block and win,<br /> If a=0 then it is guaranteed that after each block, the attacker will be 1 more block behind the main chain, so if we are currently tied, it will take us exactly 3 blocks created until we are 3 block behind the main chain and will stop the attack.</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-11014071</guid>
				<title>HW2 Q2c</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-11014071/hw2-q2c</link>
				<description></description>
				<pubDate>Sun, 07 Apr 2019 00:14:57 +0000</pubDate>
				<wikidot:authorName>Eden F.</wikidot:authorName>								<content:encoded>
					<![CDATA[
						 <p>Do we need to prove the statement for the trivial protocol of testing random strings, or do we need to prove that it holds for any (optimal) protocol?</p> 
				 	]]>
				</content:encoded>							</item>
					<item>
				<guid>http://blockchains-tau-s19.wikidot.com/forum/t-10993259</guid>
				<title>HW2 Q2B</title>
				<link>http://blockchains-tau-s19.wikidot.com/forum/t-10993259/hw2-q2b</link>
				<description></description>
				<pubDate>Fri, 05 Apr 2019 13:39:08 +0000</pubDate>
				<wikidot:authorName>matan matzliach</wikidot:authorName>				<wikidot:authorUserId>5278232</wikidot:authorUserId>				<content:encoded>
					<![CDATA[
						 <p>Hey,<br /> Can we get a clarification about what are the criteria for a good proof of work?<br /> Is it just that it takes a long time (yet not too long) to solve one and short time to verify it?<br /> Should we refer to non-amortization and difficulty parameter (how to set one) as well?</p> <p>Also is k fixed and is i public to everyone?</p> 
				 	]]>
				</content:encoded>							</item>
				</channel>
</rss>