The encryption/hashing doesn't really add anything beyond empty marketing. The trusted party who ppl report to could easily work out all of the names of they wanted to.
The encryption/hashing doesn't really add anything beyond empty marketing. The trusted party who ppl report to could easily work out all of the names of they wanted to.
Edit: HE scheme (lwe) works on individual bits. Meaning there are only two plaintexts (0,1). Each has exponentially many ciphertexts, only one chosen at random. They also share ciphertext space, meaning each ciphertext could be either encrypted zero or one.
1) Initial report is filed.
2) Second report is filed by a user who only knows the attackers details.
3) Match is found
Therefore you can just keep iterating through names till you get a match.
Another way of saying it is that the application won't work if a second user can't tell that the first user has entered an attackers name.
The vulnerability is in the application specification, not HE.
Edit: I realize you’re probably talking about Callisto which does seems like simple hashing of names, but I wanted to note that this is not always the case in apps using ZK proofs and FHE which the article touches on a bit later.