Loading video...

Video Failed to Load

Go Home

BITCOIN RAILS #72: Bitcoin's Leading Post-Quantum Signature Proposal | with SHRINCS co-author conduition 🔗 YouTube: 🌿 Spotify: The first fully specified post-quantum signature scheme for Bitcoin has been proposed to the Bitcoin mailing list. The proposal introduces a full specification for “SHRINCS,” a hash-based signature scheme initially conceived by...

15,429 views • 15 days ago •via X (Twitter)

0 Comments

No comments available

Comments from the original post will appear here

Related Videos

BITCOIN RAILS #59: Post-Quantum Bitcoin Signatures (+ their tradeoffs) | with BIP 360 co-author Ethan ✨ is on BlueSky✨ Heilman 🐱 and Blockstream Head of Research Jonas Nick 🔗 YOUTUBE: 🌿 SPOTIFY: According to BIP 360 co-author Ethan Heilman, Bitcoin needs a minimum of two soft forks to become quantum resistant: P2MR (or an output type that can safely execute PQ signatures) + a post-quantum checksig (signature scheme). Ethan and the BIP 360 team (including myself and Hunter Beast 🕯️) introduced the P2MR part via a BIP 360 update late last year—but the question remains, what’s the most appropriate PQ signature scheme for Bitcoin? They all have substantive tradeoffs, but hash-based signatures seem to be leading technical discourse—likely due to recent optimizations by Jonas Nick and the broader Blockstream research team. It was an honor to sit down with both of these men - arguably the two most influential and productive cryptographers in Bitcoin quantum mitigation right now - for an in-depth review of the leading PQ signature schemes and a temperature check on Bitcoin’s post-quantum planning process. TBH, if you want to skip the noise and jump straight to the signal on quantum, this is the interview to watch. In this episode, we discuss: - What needs to happen at the soft fork, infra, and mitigation levels to fully quantum-harden Bitcoin - Recent updates to BIP 360 + breakdown of the leading hash-based signatures schemes for Bitcoin (SHRINCS + SHRIMPS) - Why we may actually get consensus around a stateful scheme for Bitcoin - Comparisons of hash-based signatures vs Lattice and Isogeny-based schemes - Assessing the risks of both waiting too long and acting too fast (and why quantum is a better threat to be facing than a potential classical attack) This episode of Bitcoin Rails is brought to you by my NEW sponsors: - LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) - Hashi on Sui — a primitive for executing Bitcoin Defi transactions, without having to trust a federated bridge or other centralized entity - BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 Intro 02:18 Ethan’s Quantum Wakeup 05:18 How Blockstream Enters Post Quantum 09:25 BIP 360 Explained 12:11 How Bitcoin Transitions to PQ 17:35 Choosing Post Quantum Signatures 23:20 How Blockstream Created SHRINCS 27:22 Signature Budgets Importance Explained 41:13 What are SHRIMPS? 44:51 SHRIMPS vs SHRINCS 47:48 Why SLH-DSA Alone Won’t Cut It 49:24 Is a SHRIMPS + SHRINCS BIP Coming? 51:51 Blockstream’s Big Plans for Liquid 59:04 Quantum Readiness Roadmap 01:02:22 Importance of a PQ Recovery Plan 01:05:35 How Long Would a PQ Migration Take 01:11:17 Quantum Watchlist Recommendations

Isabel Foxen Duke⚡️

24,109 views • 4 months ago

BITCOIN RAILS #70: THE CASE FOR LATTICE-BASED SIGNATURES IN BITCOIN | with CTO of Ledger Charles Guillemet 🔗 YouTube: 🌿 Spotify: To date, post-quantum Bitcoin discussions have largely centered on which digital signature schemes offer the strongest cryptographic security against a quantum adversary. But cryptographic assumptions are only one dimension of security. Different signature schemes introduce different implementation and operational risks. How should Bitcoin weigh cryptographic conservatism against the complexity required to deploy that cryptography safely? While hash-based signatures are often favored for their conservative assumptions, CTO of Ledger, Charles Guillemet Charles Guillemet argues that evaluating primitives in isolation can obscure consequential risks at the systems level. Stateful hash-based schemes, in particular, introduce state-management requirements where operational or user error can have catastrophic consequences —despite their conservative cryptographic foundations. In this interview, Charles and I examine the tradeoffs of hash-based signatures and his case for greater consideration of lattice-based alternatives, i.e. ML-DSA. A very juicy episode for anyone seriously assessing Bitcoin's post-quantum design landscape. This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro 01:45 — How the quantum threat became real for Ledger 09:06 — NIST influence and what Ledger built into its SDK 21:25 — ML-DSA and why Falcon might not be the right choice 25:33 — The problem with hash-based signatures 31:38 — Stateful signatures and the throughput problem 36:48 — Does user error outweigh the security difference? 42:27 — Bitcoin post-quantum migration scenario 45:15 — Maintaining multisig capabilities in a post-quantum world 55:54 — NIST standardization process and the backdoor question 1:01:06 — Trezor's approach and device authentication 1:06:09 — Ledger’s approach to post-quantum signatures

Isabel Foxen Duke⚡️

18,721 views • 17 days ago

BITCOIN RAILS #71: Expecting Hardforks | with Drivechains author Paul Sztorc 🔗 YouTube: 🌿 Spotify: Paul Sztorc founder and CEO of LayerTwo Labs and author of Bitcoin Improvement Proposals 300 and 301 (Drivechains), has been one of Bitcoin's most persistent—and controversial—thinkers, advocating for merge-mined sidechains as a way to dramatically expand Bitcoin's functionality while preserving the security of the base layer. Following our previous episode introducing his proposed Bitcoin hard fork, eCash, we discuss how the project has evolved in recent months, what to expect when the fork launches on mainnet, and Paul's perspectives on today's Layer 2 landscape and the soon-to-activate BIP 110 soft fork. An entertaining, popcorn-style conversation with one of Bitcoin's most unconventional thinkers, this episode offers diverse—and at times irreverent—commentary on some of the most important technical debates shaping Bitcoin's future. This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro 00:16 — The Coldcard exploit 09:37 — Can Bitcoin still soft fork? 15:30 — Paul's hard fork 26:12 — BIP 110's fork and the ghost of SegWit 42:03 — How drivechains work and eCash 53:00 — Quantum resistance and OP_CAT 1:01:44 — Launching a drivechain and the OP_RETURN debate 1:08:57 — The BIP 110 endgame: Udi trolling, hashrate, and Ocean 1:13:54 — Why Stratum V2 is a bad idea 1:20:33 — The decline of maximalism and the road ahead

Isabel Foxen Duke⚡️

18,808 views • 1 month ago

BITCOIN RAILS #61: QUANTUM CRYPTOGRAPHY FOR BITCOIN | with Dan Boneh Dan Boneh 🔗 YOUTUBE: 🌿 SPOTIFY: One of the most prolific and influential cryptographers in the world, it’s difficult to fully quantify the impact that Dan Boneh has had on Bitcoin and digital assets more broadly. Through both his own research and his mentorship of some of the space’s most important contributors — e.g. Andrew Poelstra, Benedikt Bünz ☕️, and Robin Linus — few people have done more to shape the cryptographic foundations underlying modern blockchains and digital finance. More recently, Dan co-authored Google's widely discussed paper, “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities,” which reduced prior estimates of the resources required to run Shor’s algorithm against the elliptic-curve cryptography used by Bitcoin. The paper reignited debate around quantum computing timelines and the long-term security assumptions behind modern cryptocurrencies. In this episode of Bitcoin Rails, Dan and I discuss the current state of quantum computing, its potential implications for Bitcoin, and how he believes the Bitcoin community should think about preparing for a post-quantum future over the coming decade and beyond. And yes, Dan shares his take on the “when quantum” question in the interview, among other key perspectives. This episode of Bitcoin Rails is brought to you by my NEW sponsors: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin Defi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro and Dan’s history with cryptography and Bitcoin 11:44 — Shor's algorithm: how a 1994 paper became cryptography's most important threat 16:39 — Building a quantum computer: superconducting qubits vs neutral atoms 25:37 — When should we start worrying about quantum computers? The timeline debate 31:51 — Have we already reached quantum computing's “ahá” moment? 39:09 — Inside the Google paper: how Shor's algorithm was optimized 49:57 — The Bitcoin mempool attack and the 10-minute window 59:21 — Mitigation: what should Bitcoin do to prepare for quantum? 1:11:54 — Hash-based vs lattice-based signatures: Dan's case for lattice 1:23:15 — ZK proofs, BIP361, and what to do with Satoshi's coins 1:31:52 — Encrypted mempools and MEV 1:38:29 — Why Bitcoin will survive quantum and Dan's message to Bitcoin builders

Isabel Foxen Duke⚡️

114,934 views • 3 months ago

BITCOIN RAILS #62: BITCOIN'S 3 BIGGEST CHALLENGES | with Neha Narula Director of Digital Currency Initiative (DCI) Massachusetts Institute of Technology (MIT) 🔗 YOUTUBE: 🌱 SPOTIFY: Neha Narula is the Director of the MIT Digital Currency Initiative, where she focuses on Bitcoin research and the broader design tradeoffs of decentralized money systems. Her work often centers on what Bitcoin gets right—and where it runs into hard limits—especially around scaling, decentralization, and how systems behave as global demand increases. In this interview, Neha and I explore longer-term risks to Bitcoin—including advancements in quantum computing and the implications of a diminishing block subsidy—as well as the ongoing challenge of scaling Bitcoin without losing access to self-custody. A thoughtful conversation on how Bitcoin may change in the coming years, we also explore its social and governance dynamics—including tensions within the development community over protocol changes, scaling philosophies, and the future direction of the system. This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin Defi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox— an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 Intro 00:17 Neha’s Origins 02:26 Bitcoin to MIT 04:40 Media Lab Culture and Mission 11:34 CBDCs as Digital Cash Debate 24:42 Funding Model and Bitcoin Security Budget 29:55 Reorg Risk and Quantum Computing 32:14 Bitcoin Dev Funding Map 42:49 Governance and Corporate Stakes 50:23 Quantum Tradeoffs Framework 56:02 Post Quantum Proposals 58:59 Prioritize PQ Transactions 01:00:54 Satoshi Coins Debate 01:02:12 Mining Incentives And Price 01:08:08 Corporate Funding And Governance 01:10:54 Scaling Self Custody And L2s 01:20:30 Bitcoin Kernel And Wrap Up

Isabel Foxen Duke⚡️

24,482 views • 3 months ago

BITCOIN RAILS #69: ZERO-KNOWLEDGE PROOFS FOR POST-QUANTUM BITCOIN | with Benedikt Bünz 🔗 YOUTUBE: 🌿 SPOTIFY: While many Bitcoiners remain hopeful the network will embrace zero-knowledge proofs for protocol-level use cases, practical adoption has remained limited outside of BitVM and a handful of experimental proposals. Most of the world’s ZKP research has circled around Ethereum and other ecosystems, where significant resources have been dedicated to advancing these systems, particularly for scaling and privacy applications. One of the most notable contributors to this research is Benedikt Bünz ☕️ — professor of cryptography at NYU and collaborator of Dan Boneh, who together inarguably form one of the strongest blockchain-applied cryptography teams in the world. The pair recently announced they’ll be leading the new post-quantum cryptography unit localhost research — the first dedicated PQ research effort within a major Bitcoin development organization. With Benedikt leading the charge on the use of zero-knowledge proofs for post-quantum mitigation, the question emerges: will the post-quantum transition be the catalyst to finally bring zero-knowledge proofs to Bitcoin's core protocol? In more detail, Benedikt and I discuss: - Why ZKPs haven’t been widely adopted by the Bitcoin technical community — and why the threat of quantum computers may change that posture going forward - How ZKPs could be used for signature batching to address larger post-quantum signatures in Bitcoin’s post-quantum era - Why Bitcoiners will likely prioritize hash-based signatures as an initial post-quantum scheme — rather than more efficient but less proven alternatives (e.g., lattice-based) - How ZKPs have evolved over the last decade and may finally be ready for Bitcoin’s strict requirements around trust assumptions - Why Benedikt and Dan are teaming up with localhost research to create the first post-quantum cryptography unit within a major Bitcoin development organization + what they hope to accomplish This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro 00:22 — Benedikt's background 04:10 — How Benedikt got into Bitcoin and cryptography 07:42 — First ZK project: proving exchange solvency after Mt. Gox 16:01 — ZK proofs explained 27:43 — How security gets popular & ZK proofs in Bitcoin 35:49 — Other applications of ZK proofs for Bitcoin 40:15 — Why ZK proofs haven't been adopted in Bitcoin 50:46 — Why the Bitcoin post-quantum transition needs ZK proofs 01:07:00 — Cryptographic agility and why lattices win 01:18:00 — The size problem and how SNARKs solve it 01:33:57 — Proving a Bitcoin block in a laptop in 1.5 seconds 01:37:12 — Bitcoin as the primary quantum target 01:40:47 — ZK proofs for seed phrase recovery

Isabel Foxen Duke⚡️

19,872 views • 1 month ago

BITCOIN RAILS #63: Bitcoin's threshold for trust-minimization—without a soft fork | with Sam Blackshear Sam Blackshear 🔗 YOUTUBE: 🌱 SPOTIFY: Some of the most impressive technical and commercial leaders in digital assets emerged from what insiders call the "Libra Mafia" — the team assembled by Meta to build Libra (later Diem). Though the project ultimately succumbed to regulatory pressure, it produced a generation of founders and engineers who went on to shape the industry, including Sam Blackshear (Sam Blackshear), a leading expert in blockchain programming languages and CTO of MystenLabs.sui In this episode of Bitcoin Rails, Sam joins me to discuss: - Why Mysten Labs has turned its focus toward Bitcoin + why Sam leans conservative on soft-fork changes to Bitcoin script - What makes a strong crypto programming language + why EVM is missing the mark - Why trust minimization remains the critical technical challenge standing between Bitcoin and broader DeFi adoption - Why Mysten Lab's new Hashi architecture may be the most trust-minimized architecture for Bitcoin "bridging" without a soft fork This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro 01:09 — Sam's Origin Story 04:40 — Building Move Inside Libra 10:18 — Why Sui Looks Like Bitcoin 15:55 — Libra Dies & Sui Is Born 23:06 — Quantum Resistance & Sui's Cryptography 28:24 — Bitcoin's Programmability Problem 34:39 — How Hashi Works 38:00 — Hashi's Trust Assumptions 53:54 — Why Nobody Else Could Build This 56:24 — The Future of Building on Bitcoin

Isabel Foxen Duke⚡️

34,558 views • 3 months ago

Can a sufficiently powerful quantum computer forge the signatures used to authorize Bitcoin and Ethereum transactions? What would it take to upgrade both networks before that happens? In this new lecture, Stanford cryptographer Dan Boneh explores why blockchains may turn to signatures built from hash functions. He also presents new research on threshold signing. The talk ends with the questions Bitcoin still has to answer, including whether post-quantum signatures will require larger blocks, what happens to abandoned coins, and how someone such as Satoshi could prove ownership after Bitcoin’s current signatures have been retired. 00:00 Why blockchains need to prepare for quantum computers 03:05 Why Bitcoin may bet on hash-based signatures 06:25 The “big footgun” in stateful signatures 08:58 A quantum-safe signature that takes one billion hashes 14:13 Inside SLH-DSA’s virtual tree 20:30 How Bitcoin and Ethereum could make the switch 23:48 What happens when a wallet loses its state? 32:47 Can threshold signing survive the quantum transition? 36:39 How to hide lattice cryptography from the blockchain 38:49 Why threshold one-time signatures seem impossible 45:36 How context prevents forged signatures 49:37 The forgotten idea behind Winternitz signatures 54:50 Turning one-time signatures into threshold signatures 1:04:27 Will quantum-safe signatures require bigger Bitcoin blocks? 1:06:26 Abandoned bitcoin and Satoshi’s recovery problem

a16z crypto

118,792 views • 17 days ago

BITCOIN RAILS EPISODE #18: MAKE BITCOIN QUANTUM RESISTANT | with BIP360 author Hunter Beast Hunter Beast 🕯️ Quantum computing is a complicated topic—one that incites equal amounts of fear and skepticism depending on who you talk to… especially in Bitcoin. In this episode, BIP360 author Hunter Beast wisely shares why the “truth is likely somewhere in the middle,” citing incremental advancements in quantum computing that may eventually pose a legitimate threat to some Bitcoin addresses—as well as steps we can take to protect ourselves in the short, medium and long term. The correct posture is to “be prepared, not scared,” says Hunter Beast 🕯️ Ultimately, the introduction of quantum resistant cryptography—via proposals like BIP360—will be needed for higher degrees of security. That said, individuals can mitigate personal risk substantially through proper address-use hygiene. This episode breaks down the specific challenges Bitcoin will face in the event of a quantum attack, the likelihood of an attack over time, and the steps we’ll need to take at the individual and communal level to ensure Bitcoin’s safety. This episode includes detailed discussion of: 1) How quantum computing could potentially affect Bitcoin public/private key cryptography—and technologies built on vulnerable addresses (e.g. Taproot) 2) Best practices for protecting yourself against quantum in the short and long term 3) Implications of vulnerable address types—e.g. what about Satoshi’s coins? 4) Deep Dive into BIP360 + proposed long-term solutions 5) Industry roadmaps for quantum computing + how banks and governments are preparing for “Q Day” As always, this episode can be viewed on Spotify or YouTuve—full episode in the comments or linktree in my bio. This episode is powered by Best In Slot—the leading API for Ordinals and BRC20 data aggregation and indexing. TIMESTAMPS: 00:00 Intro 02:05 What is quantum computing? 04:30 How could quantum threaten your Bitcoin wallet? 06:50 Addresses that are safe from quantum 09:13 Satoshi’s coins are in danger! 11:25 What happens if Satoshi’s coins are touched? 14:45 Do we softfork to shield Satoshi’s coins? 16:38 “Transitory inflation” for bitcoin after quantum 21:05 Why Taproot addresses are vulnerable 23:50 Do NOT reuse your Bitcoin addresses! 26:03 When will Quantum become a threat? 28:34 The long/short exposure attack; explained 31:45 Protection using private mempools 33:20 Why all the new Bitcoin L2s are in danger 37:45 Quantum is 5 to 10 years away, governments fear 40:34 Non-Bitcoin systems threatened by quantum 42:26 Centralized systems can adapt to quantum 43:50 Hunter’s BIP: Post quantum cryptography in Bitcoin 47:40 Hunter’s three new signature algorithms 53:48 Is new cryptography on Bitcoin risky? 56:33 Why not just stick to hash-based cryptography? 58:49 A 16X discount for quantum resistant addresses? 01:02:30 Creating quantum resistant multisig addresses 01:04:00 What is Frost? 01:06:50 The long process of approving a BIP 01:08:30 What developers think of Hunter’s BIP 01:10:00 Matt Corallo’s concerns with Hunter’s approach 01:11:00 Steps to implementing the BIP 360 01:17:00 Where to learn more about BIP 360 01:17:50 Who can push the button to change Bitcoin?

Isabel Foxen Duke⚡️

31,148 views • 1 year ago

Bitcoin Rails x MARA Foundation presents: THE POLITICS OF POST-QUANTUM BITCOIN | with Nic Carter 🔗 YouTube: 🌿Spotify: Less than nine months ago, investor and researcher nic carter sparked one of the most heated debates in Bitcoin's recent history — when he published a series of essays arguing that the network should prepare for its post-quantum transition sooner rather than later. While the essays broadly persuaded investors and institutions, many of Bitcoin's technical leaders dismissed them as alarmist — that is, until Google's quantum resource estimates were updated just a few months later. Crediting Google's paper with "shifting the Overton Window" on quantum and strengthening the case for post-quantum preparation, Nic shares his thoughts on the delicate politics surrounding this transition — and how he believes a quantum attack and response could potentially play out in practice. In more detail, this special episode of Bitcoin Rails X MARA Foundation TV covers: - How a quantum attack could realistically unfold + the different ways stakeholder groups might respond - The constitutional tensions surfaced by quantum vulnerable coins and how incentives will ultimately dictate outcomes - How a state actor could facilitate "benevolent" quantum recovery and eliminate the need for a contentious fork - The role and influence of institutional investors as key players in quantum outcomes - How Bitcoin's post-quantum transition could permanently reshape Bitcoin’s governance structures ...or build them from the ground up TIMESTAMPS: 00:00 — Intro 00:18 — Nick's path from Fidelity to founding Castle Island 07:00 — How quantum went from FUD to Nick's biggest concern 12:45 — Why Core devs refuse to be accountable 26:09 — Investors vs developers: who took quantum seriously first 32:33 — Bitcoin's "pre-constitutional" governance problem 39:18 — Satoshi's coins: liquidate, burn, slow-bleed, or let the government take them 47:36 — Why there will never be another Bitcoin fork war 01:01:35 — Bitcoin is about to choose the wrong signature scheme 01:09:42 — The actual deadline: why PQ signatures need to ship in 2026 01:13:09 — The happy path, the coup, and why Bitcoin won't die

Isabel Foxen Duke⚡️

51,026 views • 2 months ago

.Sui has a massive headstart and the most flexible architecture for the post-quantum and AI era. This conversation with Kostas Kryptos tells you exactly why, and what every other chain still has to figure out. If you hold anything onchain, watch this pod. Timestamps: 0:00 Intro 6:00 What a quantum computer actually is (the 10-year-old version) 10:00 Quantum will be used for trading before it ever breaks Bitcoin? 13:00 Post-quantum algorithms (solved) vs hardware (decades out) 17:00 "If you think quantum breaks crypto by 2030, you can make free money" 19:00 Everyone missed this: AI is now researching quantum alongside humans 25:00 The post-quantum-algorithm debate: Falcon, Dilithium, Sphincs and why each chain picks differently 27:00 Why Bitcoin will ONLY adopt hash-based post-quantum algorithms 31:00 This is why Sui's architecture wins: 128KB transactions, native multi-sig, flexible authenticator 36:00 How Sui can natively support any signature scheme 40:00 The Sui-only algorithm: protect existing EdDSA addresses without moving a coin 44:00 Design philosophy: what Sui kept from Libra, and what it threw out 47:00 Why Sui can keep gas low even with post-quantum signatures 49:00 How Kostas first started working on this in 2016 at R3 Corda 51:00 Attending tech conference one day after his son was born: meeting Sam Blackshear , joining Libra 55:00 The bigger near-term threat: AI-aided attacks, not quantum 58:00 Why Mysten Labs is now sharing its security tooling with the community 1:02:00 Sui's $100K post-quantum bounty: break it, keep it

Sooraj

14,272 views • 3 months ago

Blockstream Bitcoin Hardware Wallets have Anti-Exfil. Anti-Exfil adds another layer of security by forcing the device to include random data in signatures, preventing attackers from slowly guessing your private keys. With ECDSA (the digital signature algorithm used in Bitcoin), a random private key is combined with a nonce, which is a one-time value intended to add randomness to the signature to ultimately produce a transaction signature that can be validated by other users’ Bitcoin full nodes. Anyone can guess your private key based on your signatures without this random nonce, which is as bad as it sounds! Compromised hardware wallets could create a nonce that appears random but is not. The nonces could be known to an attacker ahead of time. Even worse, the hardware wallet could leak parts of the user’s master private key into individual nonces, which would allow the attacker to guess every private key given a sufficient number of signatures. Anti-Exfil uses “sign-to-contract” to ask Jade to use its signature nonce while cryptographically committing to some random data proposed by the (assumed uncompromised) host computer. The random data’s hash is then combined with the signature nonce to produce the signature. By use of this protocol, the nonce is re-randomized, thus preventing the attack. More info: 10% off on Blockstream store products with coupon "maximus". And the code JADEPLUSEXPRESS gets anyone free expedited shipping on a Jade Plus

Maximus Maximalistus

28,668 views • 26 days ago