The Abolition of the Dealer

2026-06-02 · 6,550 words · Singular Grit Substack · View on Substack

On mental poker, and the engineering of trust among people who are right not to trust one another

Keywords: mental poker; secure multiparty computation; zero-knowledge proofs; verifiable shuffle; commitment schemes; threshold cryptography; verifiable randomness; electronic voting; distributed trust; cryptographic protocols.

Abstract. In 1979 three mathematicians asked whether two people who thoroughly distrust one another could play a fair hand of poker over the telephone, with no cards, no croupier, and no referee to appeal to. The question sounds like an after-dinner amusement; the answer turned out to be a foundation. This essay traces the idea of mental poker from its origin as the first worked example of secure two-party computation to its maturity as a general doctrine: that secrecy and proof are not enemies, that a private fact can be concealed and audited at once, and that fairness need not be entrusted to anyone’s good character when it can instead be built into the structure of the game. I describe the instruments this programme produced — commitment, semantically secure encryption, the verifiable shuffle, the zero-knowledge proof, secret sharing, and the completeness theorems of secure computation — and then argue, through five detailed applications, that the achievement reaches far beyond the card table. Sealed-bid markets, verifiable elections, unriggable public randomness, confidential audit, and keys held by no single hand are all, at bottom, the same gesture performed in different theatres: the abolition of the trusted third party. The conclusion is offered without apology. A civilisation that learns to deal honestly without a dealer has done something its moralists have only ever promised.


I. The honest game and the dishonest world

There is a particular kind of person who believes that fairness is a matter of sentiment — that if only men were nicer, the games of the world would come out right. This person is charming at dinner and ruinous at cards. The opposite kind, less charming and far more useful, observes that a game is fair not when its players are virtuous but when cheating is impossible, and sets about arranging the impossibility. The history I mean to tell is the history of the second kind of person, who looked at the oldest problem in human dealings — how to transact with someone you have every reason to suspect — and refused to answer it with a sermon.

Consider the modest scandal of a game of cards. Around a green table the players consent, without quite saying so, to a small tyranny: they appoint a dealer. The dealer shuffles where no one can follow, deals what no one can verify, and is trusted, on the strength of a uniform and a manner, to do none of the things that the position so richly invites. We call this arrangement civilised. It is in fact an act of faith dressed as a convenience. Every hand begins with a surrender — the surrender of the players’ judgment to a man whose only qualification is that he holds the deck. That we tolerate this at the casino is of no consequence. That we have built nearly every institution of commerce, governance, and record on precisely the same surrender is of the greatest consequence imaginable, and it is the quiet subject of everything that follows.

The aesthete and the rationalist, who are usually supposed to despise one another, agree on this much: a system that depends on the goodness of its officials is both ugly and unsound. Ugly, because it is a clutter of pleading and supervision where there ought to be a clean mechanism; unsound, because it stakes the outcome on the one variable no engineer should ever stake anything upon — a man’s resistance to temptation. To trust is to take out a loan against another’s character, and to pay interest on it forever. The interesting question is not how to make men trustworthy. It is how to make their trustworthiness unnecessary.

That question, posed about a card game, received a precise and astonishing answer. The answer is called mental poker, and it is one of those rare ideas that is far larger than the name it arrived under.

II. What mental poker is

The problem was set down with deliberate whimsy by Shamir, Rivest, and Adleman in a 1979 memorandum from the Laboratory for Computer Science at the Massachusetts Institute of Technology, the same three who had the previous year given the world the public-key cryptosystem that still bears their initials [1, 3]. Can two potentially dishonest players play a fair game of poker without using any cards — for example, over the telephone? The phrasing is light; the demand is severe. There are no cards, so there is nothing physical to hide behind. There is no dealer, so there is no one to blame or to trust. There is only a channel — a wire — over which two adversaries must agree on who holds what, in such a way that neither can lie about his own hand, neither can spy upon the other’s, and the shuffle is genuinely a shuffle and not a conjuring trick performed by whichever party went first.

Their paper gave two answers, and the honesty of giving both is part of its charm. To the question of whether a perfectly fair deal is possible by elementary means, the answer was a rigorous no. To the question of whether a fair and complete protocol could nonetheless be built, the answer was yes, and the construction was supplied [1]. The mechanism rests on a property that sounds like a parlour trick and behaves like a law: commutative encryption. Imagine each card placed in a box that can carry two padlocks. The first player locks every box with his own padlock and shuffles them; the second locks them again with hers and shuffles once more; and because the locks may be removed in any order, the boxes can be selectively unlocked to deal a hand without either party ever having seen, or being able to rearrange, what lies inside. In the original scheme the padlocks were exponentiations under a shared modulus, whose order of application does not matter — and out of that small commutativity an entire fair game is assembled. It was, as later commentators correctly insisted, the first example of two parties performing a secure computation rather than merely a secure transmission: not the passing of a hidden message from one who knows to one who should, but the joint production of an outcome that neither party alone is permitted to control [1].

Like all first attempts at something profound, it leaked. Coppersmith showed, with the gentle cruelty of the specialist, that a careless choice of parameters let a player extract partial information about the cards — that the masks, if cut from the wrong cloth, revealed the silhouette of the face beneath [5]. This is not a footnote; it is the moment the field grew up. For the response to Coppersmith was not to patch the trick but to ask what, exactly, it should mean for an encryption to reveal nothing — not “nothing useful,” not “nothing obvious,” but nothing whatever about the plaintext, not even a single bit of partial knowledge. Goldwasser and Micali answered that question in a paper whose very title kept the poker conceit — how to play mental poker keeping secret all partial information — and in answering it they founded the modern notion of semantic security, the standard against which encryption has been judged ever since [4]. It is a fact worth savouring that one of the load-bearing definitions of all cryptography was first stated in order to deal an honest hand of cards.

The idea would not stay at two players. Yung introduced the multi-player game and the cryptographic machinery to support it [9]; Bárány and Füredi mapped the combinatorial frontier of dealing fairly among three or more, where coalitions and the sheer geometry of distrust make the problem harder than mere doubling would suggest [8]. Crépeau sharpened the security, first against player coalitions and then to the point of concealing not only the cards but a player’s strategy — the cryptographic equivalent of a poker face that cannot be read even in principle [6, 7]. Schindelhauer assembled a toolbox of general card operations — masking, unmasking, shuffling, inserting, the verifiable handling of any card in any game — built on quadratic residuosity and, crucially, checkable by zero-knowledge proof, so that each move could be shown correct without being shown [10]. Decades on, Barnett and Smart revisited the whole edifice with the tools of discrete-logarithm cryptography, achieving a card representation whose size does not grow with the number of players, a small economy that betrays a large maturity [11]; Castellà-Roca and his collaborators pressed further still, toward protocols that tolerate a player dropping out mid-hand and that require no trusted third party at any point [12]. The toy had become a discipline, and the discipline had a thesis.

III. The deeper idea: concealment that can be audited

Strip the felt and the chips away and what remains is this. Mental poker is the art of holding a fact secret and provable in the same instant. The card in your hand must be perfectly concealed from your opponent and perfectly fixed against your own temptation to change it. It must be hidden and yet, when the moment comes, undeniable. Most of the world’s machinery assumes these two virtues to be in opposition — that to keep a thing private is to put it beyond audit, and to make it auditable is to make it public. The whole power of this body of work lies in its refusal of that assumption. It insists that secrecy and proof can be married, and it produces the marriage certificate on demand.

Here the rationalist’s favourite axiom does real labour. A thing is itself; a card is exactly one card, no more and no less, and no amount of wishing or whispering may make it two. The cryptographer’s task is to enforce that identity across a wire, among strangers, without a witness — to make the proposition this is the card you committed to, the only one, unaltered as solid as a fact of arithmetic. When that is achieved, something quietly radical has occurred. The guarantee no longer comes from a person. It comes from the structure. One does not trust the dealer to have dealt fairly; one verifies that no other deal was possible. The difference between those two sentences is the difference between a courtier’s world and a free one.

And once the dealer is seen for what he is — a single point of trust, which is to say a single point of failure and a single point of betrayal — he begins to appear everywhere, wearing other costumes. He is the auctioneer who alone sees the sealed bids. He is the election official who alone counts the ballots in a closed room. He is the lottery operator who alone knows whether the draw was honest. He is the custodian who alone holds the key to the vault, the clearing house that alone reconciles the ledgers, the platform that alone decides what your data may say about you. In every case the same bargain is struck: surrender your judgment to an intermediary and pray he is better than his opportunities. Mental poker is the proof of concept for declining that bargain. It is the demonstration, in the most disarming possible setting, that the intermediary can be dissolved into mathematics and the game played straight regardless of who would have liked to bend it.

IV. The instruments of a bloodless revolution

A revolution that abolishes a tyrant must have something to put in his place, and the something here is a small set of instruments of uncommon elegance. Each deserves to be admired on its own terms, for there is a beauty peculiar to a mechanism that does exactly what it claims and claims exactly what it does.

The first is the commitment. To commit to a value is to seal it in an envelope that you cannot later alter and your counterpart cannot prematurely open — binding and hiding at once. Blum gave the canonical and faintly absurd setting: two people who do not trust each other flipping a coin by telephone, a feat that ought to be impossible and is not, because one party commits to a guess before the other reveals the flip [14]. The commitment is the cryptographic equivalent of placing a card face-down on the table and resting one’s hand upon it: the value is fixed, the future is bound, and nothing has yet been seen. Almost every honest protocol begins with this gesture, because almost every dishonesty begins with the attempt to change one’s story after the facts are in.

The second is encryption that hides everything, the semantic security born, as we have seen, from the demand to leak no partial information about a concealed card [4]. The point is not merely that the message cannot be read; it is that the ciphertext betrays nothing — not the parity of the plaintext, not whether two encryptions conceal the same value, not a single inference an adversary might find useful. An encryption that hides “most” of a secret hides none of it, in the way that a fence with one gap is not a fence. This is the rationalist’s exactingness applied to privacy: a standard that does not negotiate with “approximately.”

The third is the verifiable shuffle, and it is the jewel. To shuffle a deck is easy; to shuffle it in a way that anyone can verify was a genuine, untampered permutation, without revealing which permutation it was, is a small miracle of construction. Neff supplied a practical one — a protocol that takes a sequence of encrypted tokens, returns them re-encrypted and reordered, and emits a compact proof, checkable by any sceptic, that the output is an honest rearrangement of the input and nothing has been added, dropped, or swapped [19]. Observe what this dissolves. The dealer’s one irreplaceable function — to shuffle where no one can see — is precisely the function now performed in the open, its secrecy preserved and its honesty exposed. The man with the deck is not asked to be trusted. He is asked to prove he did not cheat, and he can.

The fourth is the zero-knowledge proof, the most philosophically impudent idea in the collection. Goldwasser, Micali, and Rackoff formalised what it means to convince someone that a statement is true while conveying nothing beyond its truth — not the reason, not the witness, not a shred of transferable knowledge [15]. One proves one holds a winning hand without showing the cards; one proves a shuffle was fair without showing the order; one proves one is entitled without showing why. To the older mind this is a contradiction — surely to prove is to reveal. The whole genius of the construction is that it is not. Knowledge, it turns out, can be demonstrated and withheld at once, which is the abstract form of the very thing mental poker required at the table.

The fifth is secret sharing, Shamir’s economical scheme for splitting a secret into many pieces such that any sufficient quorum can reconstruct it and any smaller group learns precisely nothing — not a little, nothing, in the strict information-theoretic sense [13]. The secret is hidden not behind a wall but behind arithmetic: it is encoded as a polynomial whose value is known only to those who hold enough of its points. From this single idea grows the possibility of a secret with no sole keeper, a key with no single hand, an authority distributed past the reach of any one traitor.

The sixth is not an instrument but a theorem, and it is the one that turns a card game into a doctrine. Yao asked whether two parties could jointly compute any function of their private inputs while revealing only the result — could two millionaires learn who is richer without either disclosing his wealth — and answered yes, by a method (the garbled circuit) of considerable cunning [16]. Goldreich, Micali, and Wigderson then proved the general case, and they named it with a candour that should be inscribed over the entrance to the field: How to Play Any Mental Game [17]. Their result is a completeness theorem. Given any game of incomplete information among any number of players, they showed how to produce a protocol that the players can run among themselves, leaking no private information, that yields exactly the outcome a perfectly trusted referee would have produced — provided a majority of the players are honest. Read that again with the dealer in mind. The trusted third party is not regulated, not audited, not constrained. He is proven unnecessary, in full generality, for any game one can specify. Mental poker was the first move; this was the checkmate.

V. Why this matters in information technology

We may now say plainly what the card game was always about. The central embarrassment of the information age is that we are forced, a thousand times a day, to hand our most consequential affairs to intermediaries we cannot inspect and must somehow trust — to believe the count, the balance, the draw, the ranking, the record, on the authority of whoever happens to hold the deck. The body of work that began with mental poker is the systematic dismantling of that necessity. It teaches three lessons, each of which would have seemed a paradox to an earlier age.

It teaches that we can compute on what we cannot see — that a result may be extracted from private inputs without those inputs being surrendered, so that cooperation no longer requires disclosure and one may gain the fruit of another’s data without ever being given the data itself [16, 17]. It teaches that we can agree without a sovereign — that mutually distrustful parties can converge on a single honest outcome with no umpire above them, the umpire’s role having been distributed into a protocol that no participant controls [11, 17]. And it teaches that we can make fairness checkable — that the question “was this done honestly?” can be settled by anyone, by inspection of a proof, rather than settled by faith in a reputation [15, 19].

This is a migration of the most important word in the lexicon of human dealings, the word trust, from the realm of character to the realm of structure. The older world said trust me. The world this work has built says verify me — and means it as an invitation, not a dare. It is, if one cares to see it so, a profoundly moral relocation, for it removes the occasion of betrayal rather than merely punishing it after the fact, and it does so without asking anyone to be better than he is. It is also, if one cares to see that, a profoundly beautiful one, because there is no elegance in a system held together by supervision and no end to the supervisors a dishonest world requires, whereas there is great elegance in a mechanism that simply cannot be made to lie. The remainder of this essay is a tour of five rooms in which the dealer has been shown the door.

VI. Beyond the game: five applications

1. Sealed-bid auctions and the honest market

An auction is a deck dealt face-down. Each bidder writes a number he wishes no rival to see until the proper moment, and the entire fairness of the thing depends on the bids being concealed until they are all in, then opened exactly as written, then resolved by a rule that no one may bend in his own favour. The traditional solution is the dealer in his most familiar disguise: an auctioneer or a platform that alone receives the sealed bids, alone holds them, and alone announces the result. The temptations are exquisite and the abuses well documented — the bid quietly read in advance and a confederate’s offer adjusted to match, the losing number revealed to the wrong party, the “highest bid” that happens to be the house’s friend. Every one of these is the dealer peeking at the deck.

The cryptographic auction abolishes him by composition of the instruments already described. Each bidder commits to his bid, sealing it so that it cannot later be altered and cannot prematurely be read [14]. When the bidding closes, the bids are resolved by a secure computation among the parties, or among a set of authorities none of whom can act alone, which determines the winner and the price while revealing nothing else — not the losing bids, not the runner-up’s number, not the margin [16, 17]. And the correctness of the outcome is attested by proof, so that a loser may be certain he lost honestly without ever learning what his rivals offered [15]. The result is a market in which the most private datum a participant possesses — the price at which he values the thing — is at once perfectly guarded and perfectly binding. Trade, the rationalist will note with satisfaction, is the one human relation conducted entirely by consent, in which each party advances his own interest and both emerge better than they began; it deserves machinery worthy of that dignity, and not the grubby intermediation of someone who profits by seeing what he was trusted not to see. The sealed-bid mechanism is mental poker wearing the costume of commerce: the bid is the hole card, the auctioneer is the dealer, and the dealer has been retired.

2. Elections one can actually verify

There is no more naked instance of the trusted third party than the counting of votes. A citizen marks a ballot he must keep secret, drops it into a process he cannot follow, and is informed of a total he is asked to believe. The ballot must be private — coercion and the sold vote are the price of its not being — and yet the count must be public, in the sense that any citizen ought to be able to satisfy himself that the announced result is the true sum of the true ballots, neither stuffed, nor dropped, nor quietly transposed. Secrecy of the ballot and verifiability of the count appear to pull in opposite directions, which is exactly why the polling place has for so long been a temple of trust, its honesty vouched for by officials and observers and, in the last resort, by nothing firmer than reputation.

The verifiable shuffle was built, quite explicitly, to resolve this [19]. Encrypted ballots are passed through a sequence of shuffles, each performed by a different authority, each producing a proof that it permuted and re-encrypted the ballots faithfully and altered none of them — so that the link between voter and vote is severed beyond reconstruction while the integrity of the set is preserved beyond dispute. The votes are then tallied under encryption, or decrypted only in aggregate by a quorum of authorities no one of whom can act alone, again with proofs at every step. The outcome is an election that is universally verifiable: any observer, with no special access and no need to trust any official, may check the published proofs and confirm that the announced result is the honest tally of the cast ballots, while no observer, however determined, may learn how any individual voted. This is not a marginal improvement on the closed room; it is the closed room turned to glass without the voters inside it being exposed. The shuffler shuffles in public and proves he did not cheat — which is, once more and exactly, the abolition of the dealer, performed on the most important deck a free people ever cuts.

3. Randomness that no one owns

Every honest game needs an honest source of chance, and chance is the easiest thing in the world to counterfeit. The loaded die, the marked deck, the “random” draw whose seed was known to the man who profits — these are ancient frauds, and they survive into the digital age in subtler dress, because a single party who generates the randomness can almost always exploit the privilege. Whoever controls the shuffle controls the game; whoever controls the lottery draw controls the prize; whoever controls the random selection of a leader, or a juror, or an auditee, controls far more than chance should ever be allowed to confer. The dealer’s deepest power was never the dealing. It was the shuffling — the manufacture of the randomness itself.

To produce randomness that no one owns is therefore a foundational act, and the instruments assemble naturally to perform it. The simplest construction is a commit-and-reveal among many parties: each commits to a private random value, all reveal, and the values are combined, so that the result is unbiased provided even one participant was honest, since no one could see the others’ contributions before fixing his own [14]. The more sophisticated constructions close the one loophole this leaves — the dishonest party who, seeing the others’ reveals, simply refuses to open his own commitment and so aborts a draw he dislikes. Here the verifiable delay function of Boneh, Bonneau, Bünz, and Fisch supplies the remedy [20]: a computation that demonstrably requires a long sequence of steps to evaluate, yet whose result anyone can verify quickly, and whose output is unique. Feed the combined contributions into such a function and the result cannot be predicted by anyone until the unavoidable delay has elapsed — by which time the moment for manipulation has passed — and cannot afterwards be disputed, since the output is fixed and the proof is public. The authors themselves enumerate the uses: public randomness beacons, the election of leaders in consensus protocols, and more [20]. A lottery built this way is provably fair in a sense no licensed operator can match, for its honesty is not certified by an inspector but guaranteed by construction; a random audit selected this way cannot be steered toward or away from any particular target; a leader chosen this way owes his selection to no faction. The marked deck has been replaced by a shuffle that every player performs together and none can rig, and the result belongs to no one, which is the only honest form of belonging that chance permits.

4. Confidential audit and the sovereignty of one’s own data

The modern individual is, in the matter of his own information, a tenant rather than an owner. His records sit on another’s servers; his secrets are the intermediary’s inventory; and he is asked, perpetually, to choose between two indignities — to reveal everything in order to prove anything, or to reveal nothing and prove nothing at all. He must hand over his entire financial history to demonstrate that he can afford a thing; surrender his whole medical record to establish a single fact about his health; disclose the contents of his accounts to satisfy an auditor that they balance. The premise behind every such demand is that a fact cannot be proven without the record that contains it being surrendered. That premise is false, and the instruments of mental poker are its refutation.

A zero-knowledge proof allows one to demonstrate a fact about private data without disclosing the data — to prove that one’s balance exceeds a threshold without revealing the balance, that a figure falls within a permitted range without revealing the figure, that a set of accounts reconciles without exposing the transactions within it [15]. Secret sharing and secure computation allow several parties to pool sensitive records and learn only an agreed result — an aggregate, a statistic, a yes-or-no — while each party’s contribution remains its own, so that data may be made useful without being made naked [13, 16, 17]. From these follows a form of audit that the older world could not imagine: a ledger that is confidential and auditable at once, whose entries are concealed from the idle and the hostile yet provable to the entitled, where the question “do the books balance, and was each entry properly authorised?” can be answered with certainty by a proof rather than by the surrender of the books. The intermediary who once had to be trusted with everything in order to verify anything is dissolved into a protocol that verifies without possessing. This is the application that touches the individual most nearly, for it restores to him the thing the information age quietly took: the standing to be the sole owner of facts about himself, disclosing them by his own judgment and on his own terms, neither forced into exhibition nor condemned to silence. A man’s data, like a man’s hand of cards, should be his to conceal and his to prove — and never the dealer’s to read.

5. Keys held by no single hand

The final room is the one in which the doctrine turns upon its own foundations and secures the secrets that secure everything else. A cryptographic key is the modern crown jewel; whoever holds it holds the signature, the vault, the identity, the authority it commands. To place such a key in a single hand is to recreate, in the most concentrated possible form, the very tyranny the whole programme exists to abolish — a single point of trust, which is a single point of failure and a single point of betrayal, and history is not short of custodians who proved unequal to the temptation of a key that opened everything.

Secret sharing breaks the key into shares so that no one holds it whole and only a quorum can wield it, with any smaller conspiracy learning nothing [13]. Threshold cryptography, built upon that idea, goes further: it permits the quorum to use the key — to sign, to decrypt, to authorise — without ever reconstructing it in one place, so that the key exists only as a distributed potential and never as a thing an attacker could steal entire. And the completeness theorem assures us, in full generality, that the very generation of such a key can itself be performed jointly by parties none of whom ever sees it, each contributing to a secret that belongs to all of them and to none of them [17]. The signature of an institution thus need not depend on the integrity of any one official; the authority to move what is valuable can be made to require the genuine, simultaneous consent of many, none of whom can act alone and no one of whom need be trusted absolutely. Here the original conceit reaches its purest expression. The deck is the key; the dealer who would have held it is replaced by a circle of parties who together can deal the necessary hand and individually can do nothing at all. We began by asking how to play cards with no one trusted to shuffle. We end by guarding the keys of the world the same way — which is to say, by trusting no one, and being, for once, entirely safe in doing so.

VII. The ledger and the card

These five rooms have a common architecture, and it is worth naming the beam that runs through them all. Each application requires not only that private state be concealed and proven, but that the proofs and the public moves be recorded somewhere every party can see and no party can quietly revise — a common stage on which the hands are played, a record that is append-only and adversary-resistant, so that what was committed cannot later be unsaid. Nakamoto’s contribution supplied exactly such a stage: a public, ordered, append-only ledger maintained by no central keeper, on which commitments can be posted and outcomes anchored beyond convenient revision [21]. Set the private machinery of mental poker upon that public ground and the synthesis is complete: secret state, verifiably honest, settled in the open on a record no one owns. The card is private; the table is public; and neither requires a dealer.

This is why the assembly of these ideas is so much more than the sum of a card game’s needs, and why one is right to insist that putting them together goes well beyond poker. Considered in isolation, each instrument is a clever solution to a narrow problem. Considered together, anchored on a public ledger and generalised by the completeness theorems, they constitute something far larger: a complete grammar for conducting the consequential affairs of strangers — markets, elections, lotteries, audits, the custody of authority itself — without appointing anyone to be trusted with the outcome. A poker table that can be made honest among players who would cheat if they could is a small thing. A civilisation’s worth of institutions that can be made honest on the same principle is not a small thing at all. The card game was the laboratory. The applications are the world.

VIII. Coda: the beauty of the built thing

It remains only to say why this should move us, and not merely impress us. The cynic supposes that the elimination of trust is a cold project, fit for a colder age — that to replace the handshake with a proof is to lose something warm and human. The supposition is precisely backwards, and it is worth the small impertinence of saying so plainly. What is replaced is not the handshake but the shakedown; not trust freely given between people who have earned it, but trust extorted by intermediaries who stand between us and what is ours and charge for the passage. To dissolve the dealer is not to make the world colder. It is to make it cleaner — to remove from human dealings the perpetual low fever of supervision, the auditors auditing the auditors, the watchmen who must themselves be watched, and to put in their place a mechanism that simply does what it says.

There is, in the end, an aesthetic judgment and a moral one to be made here, and they turn out to be the same judgment seen from two sides. The aesthetic judgment is that a system which cannot be made to lie is beautiful, in the exact way that a proof is beautiful and a piece of clutter is not — economical, exact, claiming no more than it delivers and delivering all that it claims. The moral judgment is that such a system is good, because it secures fairness without sacrificing anyone to anyone, because it lets each party pursue his own interest in the open and arranges that the honest outcome follows regardless of who would have preferred otherwise. These are the two faces of a single achievement, and it is the achievement of the productive, reasoning mind at its best: not the mind that exhorts men to be better, which is the cheapest and least effective thing a mind can do, but the mind that builds the structure in which their being no better than they are no longer matters.

The dealer ruled for as long as he did because we mistook our dependence on him for a fact of nature, the way every captive mistakes his cage for the shape of the world. He was abolished not by indignation, which abolishes nothing, but by construction — by a few exact people who looked at the oldest surrender in human affairs and built the machine that made it unnecessary. They began, with a straight face and a deep purpose, by asking how to deal an honest hand of cards to a man they had every reason to distrust. The answer they found turned out to be the answer to a far older question, the one every free arrangement among human beings has always been quietly asking: how to deal honestly, with no one trusted to deal. The hand has been dealt. There was no dealer. That is the whole of the revolution, and it is enough.


References

[1] A. Shamir, R. L. Rivest, and L. M. Adleman. “Mental Poker.” MIT/LCS/TM-125, Laboratory for Computer Science, Massachusetts Institute of Technology, February 1979. Published in The Mathematical Gardner, D. A. Klarner (ed.), Wadsworth International / Springer, 1981.

[2] W. Diffie and M. E. Hellman. “New Directions in Cryptography.” IEEE Transactions on Information Theory, IT-22(6):644–654, 1976.

[3] R. L. Rivest, A. Shamir, and L. M. Adleman. “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems.” Communications of the ACM, 21(2):120–126, 1978.

[4] S. Goldwasser and S. Micali. “Probabilistic Encryption and How to Play Mental Poker Keeping Secret All Partial Information.” In Proceedings of the 14th Annual ACM Symposium on Theory of Computing (STOC), pp. 365–377, 1982.

[5] D. Coppersmith. “Cheating at Mental Poker.” In Advances in Cryptology — CRYPTO ‘85, Lecture Notes in Computer Science, vol. 218, Springer, 1986.

[6] C. Crépeau. “A Secure Poker Protocol that Minimizes the Effect of Player Coalitions.” In Advances in Cryptology — CRYPTO ‘85, Lecture Notes in Computer Science, vol. 218, pp. 73–86, Springer, 1986.

[7] C. Crépeau. “A Zero-Knowledge Poker Protocol that Achieves Confidentiality of the Players’ Strategy, or How to Achieve an Electronic Poker Face.” In Advances in Cryptology — CRYPTO ‘86, Lecture Notes in Computer Science, vol. 263, pp. 239–247, Springer, 1987.

[8] I. Bárány and Z. Füredi. “Mental Poker with Three or More Players.” Information and Control, 59(1–3):84–93, 1983.

[9] M. Yung. “Cryptoprotocols: Subscriptions to a Public Key, the Secret Blocking and the Multi-Player Mental Poker Game.” In Advances in Cryptology — CRYPTO ‘84, Lecture Notes in Computer Science, vol. 196, pp. 439–453, Springer, 1985.

[10] C. Schindelhauer. “A Toolbox for Mental Card Games.” Technical Report, University of Lübeck, 1998.

[11] A. Barnett and N. P. Smart. “Mental Poker Revisited.” In Cryptography and Coding (IMACC 2003), K. G. Paterson (ed.), Lecture Notes in Computer Science, vol. 2898, pp. 370–383, Springer, 2003.

[12] J. Castellà-Roca. “Contributions to Mental Poker.” PhD thesis, Universitat Rovira i Virgili, 2005.

[13] A. Shamir. “How to Share a Secret.” Communications of the ACM, 22(11):612–613, 1979.

[14] M. Blum. “Coin Flipping by Telephone: A Protocol for Solving Impossible Problems.” In Proceedings of IEEE COMPCON, pp. 133–137, 1982.

[15] S. Goldwasser, S. Micali, and C. Rackoff. “The Knowledge Complexity of Interactive Proof Systems.” In Proceedings of the 17th Annual ACM Symposium on Theory of Computing (STOC), pp. 291–304, 1985. Journal version: SIAM Journal on Computing, 18(1):186–208, 1989.

[16] A. C. Yao. “Protocols for Secure Computations.” In Proceedings of the 23rd Annual IEEE Symposium on Foundations of Computer Science (FOCS), pp. 160–164, 1982.

[17] O. Goldreich, S. Micali, and A. Wigderson. “How to Play Any Mental Game, or A Completeness Theorem for Protocols with Honest Majority.” In Proceedings of the 19th Annual ACM Symposium on Theory of Computing (STOC), pp. 218–229, 1987.

[18] D. Chaum. “Blind Signatures for Untraceable Payments.” In Advances in Cryptology — CRYPTO ‘82, pp. 199–203, Plenum Press, 1983.

[19] C. A. Neff. “A Verifiable Secret Shuffle and Its Application to E-Voting.” In Proceedings of the 8th ACM Conference on Computer and Communications Security (CCS), pp. 116–125, 2001.

[20] D. Boneh, J. Bonneau, B. Bünz, and B. Fisch. “Verifiable Delay Functions.” In Advances in Cryptology — CRYPTO 2018, Lecture Notes in Computer Science, pp. 757–788, Springer, 2018.

[21] S. Nakamoto. “Bitcoin: A Peer-to-Peer Electronic Cash System.” Self-published white paper, 2008.


← Back to Substack Archive