Hal Finney on Rivest, Shamir, and Wagner on hard-to-verify signatures
Hal Finney posted a useful message on the Cryptography list discussing my hard-to-verify signatures problem and giving a reference to Rivest, Shamir, and Wagner who seem to have solved this problem in 1996 in a more effective way by finding a computation problem that's believed to be very hard to parallelize. (They also refer to an earlier statement of my approach and identify some problems with it.)
This is really convenient, since I'm in the middle of writing something that will mention how slow attestations might be a useful improvement to trusted computing. Thanks, Hal! (Thanks to Chris Palmer for pointing out Hal's message.)