http://monerotoruzizulg5ttgat2emf4d6fbmiea25detrmmy7erypseyteyd.onion/2018/02/19/logs-for-the-Monero-Research-Lab-meeting-held-on-2018-02-19.html
<suraeNoether> this means you have R\^(N-1) independent ring signatures, each with R members. and the question is: if Eve knows Alice has A different outputs on the whole blockchain, whcih has B outputs, and if all outputs are selected for ring signatures at uniform randomly, how likely is it that we see one of Alice's suspicious one-time keys appear in one of these R\^(N-1) ring signatures? <suraeNoether> how hard is it to look like a random sequence of transactions?