sipa changed the topic of #bitcoin-wizards to: This channel is for discussing theoretical ideas with regard to cryptocurrencies, not about short-term Bitcoin development | http://bitcoin.ninja/ | This channel is logged. | For logs and more information, visit http://bitcoin.ninja
jb55 has quit [Ping timeout: 240 seconds]
Guest82744 has joined #bitcoin-wizards
Guest82744 has quit [Client Quit]
Guest82744 has joined #bitcoin-wizards
Guest82744 has quit [Client Quit]
Guest82744 has joined #bitcoin-wizards
mlz has quit [Ping timeout: 265 seconds]
Barrett has joined #bitcoin-wizards
Barrett has quit [Quit: exit]
mlz has joined #bitcoin-wizards
Krellan has quit [Read error: Connection reset by peer]
Krellan has joined #bitcoin-wizards
rusty has quit [Ping timeout: 260 seconds]
jb55 has joined #bitcoin-wizards
jb55 has quit [Client Quit]
Guest25674 has quit [Remote host closed the connection]
tromp_ has quit [Ping timeout: 240 seconds]
tromp has joined #bitcoin-wizards
eck has joined #bitcoin-wizards
epscy_ has quit [Ping timeout: 276 seconds]
eck has quit [Client Quit]
jb55 has joined #bitcoin-wizards
epscy_ has joined #bitcoin-wizards
eck has joined #bitcoin-wizards
mdrollette has quit [Quit: ZNC 1.6.5 - http://znc.in]
mdrollette has joined #bitcoin-wizards
nuncanada has quit [Ping timeout: 260 seconds]
Cheeko has quit [Ping timeout: 260 seconds]
<Guest82744>
Sooooooo
<Guest82744>
Trades?
<sipa>
wrong channel
<gratefuldad>
this channel is for not talking. shhhh.
<contrapumpkin>
so bitcoin atom's big selling point is that it comes with atomic swaps *runs*
son0p has joined #bitcoin-wizards
dabura667 has joined #bitcoin-wizards
eck has quit [Quit: we out here]
coinsmurf has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 260 seconds]
Krellan has joined #bitcoin-wizards
Guest82744 has quit [Ping timeout: 252 seconds]
son0p has quit [Ping timeout: 240 seconds]
Belkaar has quit [Ping timeout: 240 seconds]
Belkaar has joined #bitcoin-wizards
Belkaar has joined #bitcoin-wizards
Belkaar has quit [Changing host]
intcat has quit [Ping timeout: 255 seconds]
eck has joined #bitcoin-wizards
StopAndDecrypt_ has joined #bitcoin-wizards
StopAndDecrypt has quit [Ping timeout: 248 seconds]
meshcollider has quit [Quit: Connection closed for inactivity]
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
eck has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
eck has quit [Ping timeout: 240 seconds]
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
sammi`_ has quit [Ping timeout: 252 seconds]
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
mlz has quit [Ping timeout: 240 seconds]
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
mlz has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
belcher_ has quit [Quit: Leaving]
rusty has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
jb55 has quit [Ping timeout: 252 seconds]
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 252 seconds]
meshcollider has joined #bitcoin-wizards
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
rusty has quit [Ping timeout: 240 seconds]
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
PaulTroon has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
rusty has joined #bitcoin-wizards
legogris has quit [Remote host closed the connection]
legogris has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 252 seconds]
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
MaxSan has joined #bitcoin-wizards
<MaxSan>
Do i understand this right that using MuSig style for signatures that we can have non interactivity on combining signed inputs?
<MaxSan>
so anyone can basically sign extra inputs on any transaction within their own mempool? and the original publisher of the tx would be able to validate their own transaction still?
<sipa>
MuSig is interactive
<sipa>
and not really the best choice for cross-input signature aggregation
<sipa>
what you're describing sounds more like BLS signatures (which support non-interactive aggregation)
<sipa>
though to combine extra inputs into transactions you want something like OWAS or MimbleWimble
<PaulTroon>
I thought it required interaction.. on page 5 of the paper it lists the number of rounds and the paper has 2 (rather than 3)
<sipa>
yes
<sipa>
many people seem to be reading way too much into MuSig
<PaulTroon>
Seems like andytoshi and tadge both have worked on this idea
<sipa>
yes you can aggregate 50% of Schnorr signatures non-interactively
<sipa>
but not entirely
<PaulTroon>
BLS seemms kind of like magic if it can do full non-interactive sig aggregation
Krellan has quit [Ping timeout: 252 seconds]
<PaulTroon>
the Rs, yes
Krellan has joined #bitcoin-wizards
<PaulTroon>
as far as I understand, the performance hit is primary negative for BLS, but I thought maybe there was some deeper cryptographic drawback also
<sipa>
it relies on pairing
<sipa>
which is more novel, and an additional assumption on top of elliptic curve DL
<sipa>
further, if all you get from it is block-wide aggregation rather than tx-wide aggregation... i'm very hesitant
<sipa>
block-wide aggregation breaks caching of tx validity, for example
<sipa>
or at least complicates it significantly
rusty has quit [Ping timeout: 252 seconds]
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
<PaulTroon>
Since the Rs aren't secret, can they be something derived from P? H(P) .. that would reduce what needs to be communicated
<sipa>
unfortunately, no
<sipa>
they must be chosen randomly by the signers, or they leak their private key through the s value
<PaulTroon>
ah, that makes sense
MaxSan has quit [Remote host closed the connection]
<PaulTroon>
the use case for sig aggregation I'm investigating is a bit different
<PaulTroon>
I want to make sure a signer can't remove the signatures and messages from the aggregate signature of previous signers
<sipa>
in BLS?
<PaulTroon>
I believe BLS can do this, but have not seen it used just for that
<PaulTroon>
though that seems to be true of all aggregate signature schemes
Krellan has quit [Ping timeout: 252 seconds]
<PaulTroon>
maybe it's overkill
<sipa>
i believe in BLS, if you have an aggregate, and you have seen an individual signature that is included in the aggregate, you can also remove it
Krellan has joined #bitcoin-wizards
<sipa>
in Bellare-Neven (what i'm considering to propose for bitcoin for cross-input signature aggregation), it's impossible, as every signer commits to the keys and messages of everyone
<PaulTroon>
I'm looking at a mesh network message passing use case where the nodes could keep their signature secret before aggregating it
nsxNP has joined #bitcoin-wizards
<PaulTroon>
it's different from the block compression/privacy use case I think, and my concern is only that perhaps aggregate signatures is overkill
airbreather has quit [Ping timeout: 248 seconds]
Krellan has quit [Ping timeout: 240 seconds]
Krellan has joined #bitcoin-wizards
<PaulTroon>
hearing andytoshi talk about mw and tadge talk about DLCs it seems like building on the schnorr signatures scheme has many advantages
<andytoshi>
yeah we've basically not been in contact at all, oops, it wouldn't surprise me if there's overlap. would be good to coordinate.
<instagibbs>
andytoshi, any notion of post-quantum signature schemes being linear in the same way?
jb55 has joined #bitcoin-wizards
<andytoshi>
instagibbs: yeah the LWE stuff, and generally anything lattice-based incl NTRU, looks like it's linear in the same way. but i haven't looked at it, my days have been too full
<andytoshi>
i'm hoping that when i actually read these papers, that it will turn out that all my stuff just translates immediately with no effort