We do not distinguish between information known by the exchange and
information known by the merchant in the above. As a result, this
-proves that out linking protocol \S\ref{subsec:linking} does not
proves that our linking protocol \S\ref{subsec:linking} does not
degrade privacy. We note that the exchange could lie in the linking
protocol about the transfer public key to generate coins that it can
link (at a financial loss to the exchange that it would have to square