RPOW - Reusable Proofs of Work

Anne & Lynn Wheeler lynn at garlic.com
Mon Aug 16 18:50:13 EDT 2004

At 12:36 PM 8/15/2004, R. A. Hettinga wrote:
>This is what creates trust in RPOWs as actually embodying their claimed
>values, the knowledge that they were in fact created based on an equal
>value POW (hashcash) token.

the issue in the "yes card" exploit is that you migrate the financial 
business rules out into hardware tokens (of any kind) and then do 
peer-to-peer operations between tokens.

the threat model is you attack the belief in a valid hardware token ... 
once you have that you have the mechanism for creating counterfeit tokens 
that can convince other tokens that they are valid. These counterfeit 
tokens don't tell the truth ... they are programmed to say whatever will 
convince other tokens that can be trusted.

and as per previous post ... i got hit in a sci.crypt thread with the claim 
that even 4758 can be succesfully attacked.

misc. posts discussing token attacks that 1) result in being able to 
fabricate counterfeits 2) which are acceptable in offline, peer-to-peer 
