Most interesting question is how honest members of quorum will reassign ledgers to re-gain control over "stealed by operator" funds; need they vote majority? such as 3-of-4 or so? (as far as I understand you, it will be multi-signature to protect against "one-sided onchain transaction"?)
Also, what if "random quorum member" (the one to which quorum gave the reservs to) will goes bad?
Also, need operators & quorum members to run a full node?
(sorry if too many questions...)
Login to reply
Replies (1)
before wallets will use a ledger, the operator spends the reserves to a multisig of quorum members. so during operation, the operator controls "truth", but the quorum controls "funds".
a bad operator cannot steal, they can only misattribute.
the majority of a quorum can steal, but in doing so reveal themselves to be dishonest. it is required that quorum members have their own ledgers with their own quorums of at least half the size, so by colluding to steal, a minimum of 2 or 3 other ledgers are at risk
since quorum membership is visible, wallets can choose ledgers where dishonesty would cause maximum fan-out of liability