# Panetière, frequently asked questions

**URL:** https://collective.flashbots.net/t/panetiere-frequently-asked-questions/5904
**Category:** Research
**Tags:** question, work-in-progress, flashnet
**Created:** [August 12, 2026, 6:27pm UTC](https://collective.flashbots.net/t/panetiere-frequently-asked-questions/5904 "2026-08-12T18:27:39Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![guayabyte](https://collective.flashbots.net/user_avatar/collective.flashbots.net/guayabyte/32/4_2.png) [@guayabyte](https://collective.flashbots.net/u/guayabyte)
#### Post date: [August 12, 2026, 6:27pm UTC](https://collective.flashbots.net/t/panetiere-frequently-asked-questions/5904/1 "2026-08-12T18:27:39Z")

</div>

- What is panetière?

- What is an anonymous broadcast?

- What are some previous works that have served as inspiration and building blocks for panetière?

- What is a trusted execution environment?

- Why do clients have to run in a trusted execution environment?

- What happens if a client breaks their TEE?

- What are the cryptographic primitives and constructions used in panetière?

- Is panetière secure to quantum attacks?

- What are the security guarantees of panetière?

- What are some use cases for panetière?

- What kind of use cases are not protected by anonymous broadcast protocol like panetière?

* * *

Existing anonymity solutions, such as TOR and Nym, require users to choose between weak anonymity or high latency.

- How does panetière relate to a mixnet like Nym?

- How does panetière relate to onion routing?

- 
- 

Do you have any more questions?

---

<div class="post-metadata">

### Author: ![guayabyte](https://collective.flashbots.net/user_avatar/collective.flashbots.net/guayabyte/32/4_2.png) [@guayabyte](https://collective.flashbots.net/u/guayabyte)
#### Post date: [September 18, 2026, 11:58am UTC](https://collective.flashbots.net/t/panetiere-frequently-asked-questions/5904/2 "2026-09-18T11:58:00Z")

</div>

Some questions open, left for collective exploration. If you have an answer, please share it here 🙂

- What does “no one can tell which client sent which” mean precisely?
- What is cover traffic?
- Are _round_, _execution_, and _broadcast_ different things in the draft?
- Is the TEE there for integrity only?
- Is a broken client’s misbehaviour detectable, and by whom?
- How does a message get into a vector position?
- Why would a client misbehave?
- Why not just verify the clients instead?
- How can one malicious client weaken another’s anonymity?
- Does anonymity hold against actively deviating clients?
- What are the failure modes of a broadcast?
- Is _contribution_ different from _message_?
- Does the post-quantum answer need to name LWE as well as SIS?
- Where does Panetière use a residue number system?
- Should the TEE questions move after the primitives list?
- Is the relaxed-to-full lifting part of the deployed system?
- What is the difference between relaxed and full anonymous broadcast?
- What is guaranteed output delivery?
- Are addition-hiding vector commitments new in this work?
- What is are additive multiset encodings?
- What happens when IBLT decoding fails?
- Is sending repeatedly riskier than sending once?
- Can a client react to what others say?
- What is the secret-sharing threshold?
- How do the servers’ public keys get published?
- What are better links for negacyclic rings?

Created together with Claude Opus 5, here is the [trace](https://claude.ai/share/7c252b81-3664-4c10-90d7-18de71dbe80b) 🍞🔍.
