- verification speed is the most important thing! then sig size - don't care about signing speed (eg 1000x loss for zkp may be worth it) - limited memory, limited space - need to work across hw resets without persistence - randomness generation (nadia bias paper, 6979) - problems with 6979 for MPC, incl thresholds - zkps as a solution?