Sure: there’s no indication of delivery, so you don’t even know if one of the hops in your message opened all the envelopes, took all the money, read your private note, and trashed it.
I think there’s a bonus feature to having two hops in the middle. If the sender finds that the recipient never received the message, he immediately distrusts his first hop and perhaps publishes the knowledge. If the first hop wasn’t the culprit, he either publishes the second hop’s unreliability or takes horrible devious Slytheriny vengeance on them.
So, due to mutually assured destruction, neither hop wants to defect and risk losing a nice income source permanently.
Yes, without public-key crypto or at least crypto of some sort, you easily lose any secrecy to any bad actors in the mix net. But the absence of dummy messages or very high traffic also means you don’t necessarily get anonymity either: just observe everyone in the System.
Sure: there’s no indication of delivery, so you don’t even know if one of the hops in your message opened all the envelopes, took all the money, read your private note, and trashed it.
I think there’s a bonus feature to having two hops in the middle. If the sender finds that the recipient never received the message, he immediately distrusts his first hop and perhaps publishes the knowledge. If the first hop wasn’t the culprit, he either publishes the second hop’s unreliability or takes horrible devious Slytheriny vengeance on them.
So, due to mutually assured destruction, neither hop wants to defect and risk losing a nice income source permanently.
Yes, without public-key crypto or at least crypto of some sort, you easily lose any secrecy to any bad actors in the mix net. But the absence of dummy messages or very high traffic also means you don’t necessarily get anonymity either: just observe everyone in the System.