Matthew Toseland wrote: >> But the samples for a weighted coin are independent, whereas with a hop >> counter they're not, so given enough requests the attacker always learns >> more from a weighted coin. > > Why are samples for a hop counter dependant?
The hop counter is deterministic - all the originator's requests should have the same HTL, so the attacker doesn't learn anything from additional positive samples. But with a weighted coin every linkable sample gives the attacker additional information. Cheers, Michael
