This channel is for discussing theoretical ideas with regard to cryptocurrencies, not about short-term Bitcoin development | | This channel is logged. | For logs and more information, visit
Krellan has joined #bitcoin-wizards
<contrapumpkin> <3
<RubenSomsen> sipa: how do key tree signatures compares to threshold signatures? is one objectively better, or are there use cases for both (assuming pure multisig with no further scripting)?
<sipa> RubenSomsen: key treed are accountable
<sipa> *trees
<sipa> (the signers can see which subset signed)
<RubenSomsen> Ah yeah, good point. Are there performance differences? I remember you pointed out that at some tresholds calculating the tree can take a long time.
<sipa> a threshold signature just looks like a single signature on chain
<sipa> so obviouslyz yes
<aj> is there a good reference for how threshold signatures via schnorr might work?
<RubenSomsen> Yes of course on-chain it is more efficient, I meant at contract creation time. Like if you do 500-1000 multisig, calculating an entire merkle tree will take a long time.
<RubenSomsen> I guess it is similar?
<RubenSomsen> Hopefully I am wording my question clearly enough
<RubenSomsen> I guess it is not really a practical concern if it happens off-chain
meshcollider has quit [Quit: Connection closed for inactivity]
<andytoshi> threshold signatures involve quadratic communication at setup, each signer sends some small amount of data to each other signer. at signing time it's linear
<andytoshi> in that each signer just broadcasts a small amount of stuff
<andytoshi> under no circumstances is there the combinatorial explosion that you see with keytrees
rusty has joined #bitcoin-wizards
<maaku> andytoshi: I don't think that's correct? the amount of data sent to/from each peer during setup depends on the number of signing sets they are involved with, which is combinatorial
<maaku> unless you are talking about a different scheme than I am thinking of
<andytoshi> yeah i'm thinking specifically about single thresholds
<andytoshi> i suppose you could have a combinatorial number of sets that isn't a threshold
<andytoshi> kanzure: should i correct some of benedikt's numbers ? it would become a false transcript but OTOH his numbers for ECDSA verify and for bulletproof batch verification are incorrect
<RubenSomsen> andytoshi: Thanks for explaining, that is what I was wondering about. That sounds pretty good then.
CubicEarths has joined #bitcoin-wizards
AaronvanW has joined #bitcoin-wizards
RubenSomsen has joined #bitcoin-wizards
<andytoshi> kanzure: this is an awesome compilation, thanks
<contrapumpkin> kanzure: btw, in it's possible to link into youtube at a particular time
<contrapumpkin> oh I see you did that
<contrapumpkin> sorry, was confused by the title of the page
<kanzure> "Atomic cross-chain swaps"
