sipa changed the topic of #bitcoin-wizards to: This channel is for discussing theoretical ideas with regard to cryptocurrencies, not about short-term Bitcoin development | | This channel is logged. | For logs and more information, visit
<nsh> if all of the bits in a single inner-product argued rangeproof are committed in order, then presumably the entire aggregated rangeproof is committing to ranges in some canonical order?
<andytoshi> typically all of the ranges would be the same
<andytoshi> but yes, there is an ordering that the verifier needs to understand
* nsh nods
<nsh> (i meant individual rangeproofs sorry)
Chris_Stewart_5 has joined #bitcoin-wizards
<eck> sorry, no
<geezas> great, someone is
<stevenroose> Anybody read about Hashgraph yet?
AaronvanW has joined #bitcoin-wizards
<nsh> seems the same radix economy type optimisations should be possible as with the elements CT implementation using bulletproofs
<nsh> mantissa, word escaped me for 10 minutes there :(
<nsh> shouldn't cause any problems aggregating proofs of varying significant digit precisoin
<nsh> except some minor code complexity overhead
<nsh> also btw [andytoshi], for a CT application of bulletproofs does/would the receiver derandomise the fiat-shamir heuristic to recover the amounts using a witness-extraction process?
<nsh> wasn't really elaborated but i guess it would transfer over relatively trivially from the CT implementation
<nsh> via some implicit ECDH key agreement that is used to fix the blinding factors or other overdetermine the linear system for the receiver
<nsh> which raises the question of whether the messages can be stuffed into the proof entropy again. they wouldn't survive aggregation which is good for bloat but perhaps an ephemeral encrypted message field could be of some utility while its in the mempool
<nsh> whether *messages
<waxwing> yeah i guess you could xor the message into the FS challenges and use ECDH as in the previous version. (just trying to interpret what you're saying nsh). i guess it carries across as a technique if needed.
<nsh> right, just trying to muse on whether the inner product argument constrains any more than the borromean ring composition
<nsh> doesn't seem intuitively so but i haven't worked it out
<waxwing> uhh no not sure what i'm talking about there .. would have to actually think about it
* nsh nods
<nsh> aye actually that is a lot more constrained. not sure what i was thinking
<andytoshi> nsh: you have way less entropy to stick messages into
<andytoshi> some constant number of bytes that does not increase with aggregate sigs. i think 64 bytes
<nsh> right
<nsh> was the talk at scalingbitcoin recorded/kanzure'd?
<nsh> was also presented at stanford security lunch this spring, but we don't have posthuman stenographers there, i guess
<kanzure> can't be there if i'm not told about it
<andytoshi> afaik bulletproofs were not public in any way until scaling bitcoin
<andytoshi> i think the spring talk was about an earlier idea that involved pairings and didn't really win until you aggregated
<andytoshi> vs bulletproofs which, even without aggregation, beat the pants off of the old proofs wrt both CPU time and space, and they require no new security assumptions
<andytoshi> warriors_: this is a research channel, many people read the entire scrollback, please stop filling it with chatter
Ylbam has joined #bitcoin-wizards
Emcy has joined #bitcoin-wizards
Emcy_ has quit [Ping timeout: 240 seconds]
meshcollider has joined #bitcoin-wizards
<nsh> maybe gson serialization handling changed or something
