Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

The quantum-mitigation question on every cryptographer's mind: to use hash-based or Lattice-based signatures in Bitcoin? Hash-based signature schemes—e.g. SHRINCs/SHRIMPS by Blockstream's Jonas Nick—have been called "the conservative choice" by Adam Back while Dan Boneh makes a push for lattice-based signatures. "Hash-based signatures are combinatorial in nature—and that limits a...

14,524 Aufrufe • vor 4 Monaten •via X (Twitter)

0 Kommentare

Keine Kommentare verfügbar

Kommentare vom Original-Post werden hier angezeigt

Ähnliche Videos

BITCOIN RAILS #70: THE CASE FOR LATTICE-BASED SIGNATURES IN BITCOIN | with CTO of Ledger Charles Guillemet 🔗 YouTube: 🌿 Spotify: To date, post-quantum Bitcoin discussions have largely centered on which digital signature schemes offer the strongest cryptographic security against a quantum adversary. But cryptographic assumptions are only one dimension of security. Different signature schemes introduce different implementation and operational risks. How should Bitcoin weigh cryptographic conservatism against the complexity required to deploy that cryptography safely? While hash-based signatures are often favored for their conservative assumptions, CTO of Ledger, Charles Guillemet Charles Guillemet argues that evaluating primitives in isolation can obscure consequential risks at the systems level. Stateful hash-based schemes, in particular, introduce state-management requirements where operational or user error can have catastrophic consequences —despite their conservative cryptographic foundations. In this interview, Charles and I examine the tradeoffs of hash-based signatures and his case for greater consideration of lattice-based alternatives, i.e. ML-DSA. A very juicy episode for anyone seriously assessing Bitcoin's post-quantum design landscape. This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro 01:45 — How the quantum threat became real for Ledger 09:06 — NIST influence and what Ledger built into its SDK 21:25 — ML-DSA and why Falcon might not be the right choice 25:33 — The problem with hash-based signatures 31:38 — Stateful signatures and the throughput problem 36:48 — Does user error outweigh the security difference? 42:27 — Bitcoin post-quantum migration scenario 45:15 — Maintaining multisig capabilities in a post-quantum world 55:54 — NIST standardization process and the backdoor question 1:01:06 — Trezor's approach and device authentication 1:06:09 — Ledger’s approach to post-quantum signatures

Isabel Foxen Duke⚡️

18,721 Aufrufe • vor 1 Monat

Can a sufficiently powerful quantum computer forge the signatures used to authorize Bitcoin and Ethereum transactions? What would it take to upgrade both networks before that happens? In this new lecture, Stanford cryptographer Dan Boneh explores why blockchains may turn to signatures built from hash functions. He also presents new research on threshold signing. The talk ends with the questions Bitcoin still has to answer, including whether post-quantum signatures will require larger blocks, what happens to abandoned coins, and how someone such as Satoshi could prove ownership after Bitcoin’s current signatures have been retired. 00:00 Why blockchains need to prepare for quantum computers 03:05 Why Bitcoin may bet on hash-based signatures 06:25 The “big footgun” in stateful signatures 08:58 A quantum-safe signature that takes one billion hashes 14:13 Inside SLH-DSA’s virtual tree 20:30 How Bitcoin and Ethereum could make the switch 23:48 What happens when a wallet loses its state? 32:47 Can threshold signing survive the quantum transition? 36:39 How to hide lattice cryptography from the blockchain 38:49 Why threshold one-time signatures seem impossible 45:36 How context prevents forged signatures 49:37 The forgotten idea behind Winternitz signatures 54:50 Turning one-time signatures into threshold signatures 1:04:27 Will quantum-safe signatures require bigger Bitcoin blocks? 1:06:26 Abandoned bitcoin and Satoshi’s recovery problem

a16z crypto

119,977 Aufrufe • vor 1 Monat

BITCOIN RAILS #59: Post-Quantum Bitcoin Signatures (+ their tradeoffs) | with BIP 360 co-author Ethan ✨ is on BlueSky✨ Heilman 🐱 and Blockstream Head of Research Jonas Nick 🔗 YOUTUBE: 🌿 SPOTIFY: According to BIP 360 co-author Ethan Heilman, Bitcoin needs a minimum of two soft forks to become quantum resistant: P2MR (or an output type that can safely execute PQ signatures) + a post-quantum checksig (signature scheme). Ethan and the BIP 360 team (including myself and Hunter Beast 🕯️) introduced the P2MR part via a BIP 360 update late last year—but the question remains, what’s the most appropriate PQ signature scheme for Bitcoin? They all have substantive tradeoffs, but hash-based signatures seem to be leading technical discourse—likely due to recent optimizations by Jonas Nick and the broader Blockstream research team. It was an honor to sit down with both of these men - arguably the two most influential and productive cryptographers in Bitcoin quantum mitigation right now - for an in-depth review of the leading PQ signature schemes and a temperature check on Bitcoin’s post-quantum planning process. TBH, if you want to skip the noise and jump straight to the signal on quantum, this is the interview to watch. In this episode, we discuss: - What needs to happen at the soft fork, infra, and mitigation levels to fully quantum-harden Bitcoin - Recent updates to BIP 360 + breakdown of the leading hash-based signatures schemes for Bitcoin (SHRINCS + SHRIMPS) - Why we may actually get consensus around a stateful scheme for Bitcoin - Comparisons of hash-based signatures vs Lattice and Isogeny-based schemes - Assessing the risks of both waiting too long and acting too fast (and why quantum is a better threat to be facing than a potential classical attack) This episode of Bitcoin Rails is brought to you by my NEW sponsors: - LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) - Hashi on Sui — a primitive for executing Bitcoin Defi transactions, without having to trust a federated bridge or other centralized entity - BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 Intro 02:18 Ethan’s Quantum Wakeup 05:18 How Blockstream Enters Post Quantum 09:25 BIP 360 Explained 12:11 How Bitcoin Transitions to PQ 17:35 Choosing Post Quantum Signatures 23:20 How Blockstream Created SHRINCS 27:22 Signature Budgets Importance Explained 41:13 What are SHRIMPS? 44:51 SHRIMPS vs SHRINCS 47:48 Why SLH-DSA Alone Won’t Cut It 49:24 Is a SHRIMPS + SHRINCS BIP Coming? 51:51 Blockstream’s Big Plans for Liquid 59:04 Quantum Readiness Roadmap 01:02:22 Importance of a PQ Recovery Plan 01:05:35 How Long Would a PQ Migration Take 01:11:17 Quantum Watchlist Recommendations

Isabel Foxen Duke⚡️

24,109 Aufrufe • vor 4 Monaten

BITCOIN RAILS #72: Bitcoin's Leading Post-Quantum Signature Proposal | with SHRINCS co-author conduition 🔗 YouTube: 🌿 Spotify: The first fully specified post-quantum signature scheme for Bitcoin has been proposed to the Bitcoin mailing list. The proposal introduces a full specification for “SHRINCS,” a hash-based signature scheme initially conceived by Jonas Nick and Mikhail Kudinov of Blockstream Research Blockstream — with specification details added by new co-authors conduition remix and BIP 360 co-author Ethan ✨ is on BlueSky✨ Heilman 🐱 Today, I’m honored to share a full whiteboard explanation of the scheme by its co-author Conduition — as well as a thorough discussion of the scheme’s key tradeoffs when compared to Bitcoin’s existing elliptic-curve signatures and competing post-quantum alternatives. In more detail, this interview includes: — A full whiteboard walkthrough of the scheme’s key components and its relationship to the NIST-standardized scheme SPHINCS+ — SHRINCs’ introduction of a compact stateful path - yes, I said stateful 🌶️ — Whiteboard explanations of all relevant cryptographic subschemes, including FORS, WOTS+C, and XMSS — Thorough discussion of the scheme’s tradeoffs and implications for Bitcoin’s existing functionality If you have a vested interest in understanding what may be the future signature scheme protecting Bitcoin transactions in a post-quantum world, this episode is a must-watch. WARNING: this episode is fairly technical — don't beat yourself up if you don't catch everything, or need to watch it a few times to grok the details. This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro 01:26 — The SHRINCS BIP and how conduition got here 05:26 — Building slhvk and joining the Blockstream working group 08:34 — Why hash-based signatures, even without quantum 14:08 — What SPHINCS is and what stateless really means 18:45 — Losing count and why state is dangerous 24:44 — SHRINCS and the stateless backup WHITEBOARD SESSION STARTS HERE: 30:30 — Inside the SHRINCS public key 34:39 — Winternitz signatures and hypertrees 43:18 — Signature sizes and witness discount 51:42 — Inside the stateful side and FXMSS 1:01:25 — Where the stateful and stateless sides differ 1:08:50 — UXMSS, BXMSS and getting wallet devs up to speed 1:19:03 — FORS and the forest of random subsets 1:34:24 — What Bitcoin gives up with hash-based signatures 1:39:08 — Migration and where SHRINCS could be deployed

Isabel Foxen Duke⚡️

15,763 Aufrufe • vor 29 Tagen

WOW 🚨 Michigan Democrats are invalidating signatures gathered by residents to block proof of citizenship and voter ID being on their November ballot Americans gathered over 700,000 signatures to put a proposed constitutional amendment in Michigan on the ballot in November for proof of citizenship and voter ID requirement Democrats are rejecting the signatures and claiming they are invalid to block the proposed amendment 709,000 signatures were submitted by Americans for Citizen Voting in Michigan Democrat took 1,000 signatures as a sample. In the sample, 629 needed to be valid to verify the signatures. Democrats said only 624 were valid so they are trying to reject the signatures because of this Democrats invalidated 5 signatures below the required amount, making sure the motion couldn’t move forward But keep in mind, Republicans gathered 709,000. So because Democrats say they were only able to validate 624 of a 1,000 signature sample, they are saying 267,000 of the 709,000 signatures are invalid So because of 5 signatures Democrats invalidated, they are saying that 267,000 signatures must be invalid and trying to reject it being on the ballot We all know the real reason why Democrats made sure to invalidate just enough signatures of the original 1,000 signature samples. They did it to MAKE SURE that a proof of citizenship and voter ID constitutional amendment doesn’t come up for a vote Democrats are rigging our elections

Wall Street Apes

138,167 Aufrufe • vor 23 Tagen

BITCOIN RAILS #61: QUANTUM CRYPTOGRAPHY FOR BITCOIN | with Dan Boneh Dan Boneh 🔗 YOUTUBE: 🌿 SPOTIFY: One of the most prolific and influential cryptographers in the world, it’s difficult to fully quantify the impact that Dan Boneh has had on Bitcoin and digital assets more broadly. Through both his own research and his mentorship of some of the space’s most important contributors — e.g. Andrew Poelstra, Benedikt Bünz ☕️, and Robin Linus — few people have done more to shape the cryptographic foundations underlying modern blockchains and digital finance. More recently, Dan co-authored Google's widely discussed paper, “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities,” which reduced prior estimates of the resources required to run Shor’s algorithm against the elliptic-curve cryptography used by Bitcoin. The paper reignited debate around quantum computing timelines and the long-term security assumptions behind modern cryptocurrencies. In this episode of Bitcoin Rails, Dan and I discuss the current state of quantum computing, its potential implications for Bitcoin, and how he believes the Bitcoin community should think about preparing for a post-quantum future over the coming decade and beyond. And yes, Dan shares his take on the “when quantum” question in the interview, among other key perspectives. This episode of Bitcoin Rails is brought to you by my NEW sponsors: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin Defi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro and Dan’s history with cryptography and Bitcoin 11:44 — Shor's algorithm: how a 1994 paper became cryptography's most important threat 16:39 — Building a quantum computer: superconducting qubits vs neutral atoms 25:37 — When should we start worrying about quantum computers? The timeline debate 31:51 — Have we already reached quantum computing's “ahá” moment? 39:09 — Inside the Google paper: how Shor's algorithm was optimized 49:57 — The Bitcoin mempool attack and the 10-minute window 59:21 — Mitigation: what should Bitcoin do to prepare for quantum? 1:11:54 — Hash-based vs lattice-based signatures: Dan's case for lattice 1:23:15 — ZK proofs, BIP361, and what to do with Satoshi's coins 1:31:52 — Encrypted mempools and MEV 1:38:29 — Why Bitcoin will survive quantum and Dan's message to Bitcoin builders

Isabel Foxen Duke⚡️

115,035 Aufrufe • vor 4 Monaten

Blockstream Bitcoin Hardware Wallets have Anti-Exfil. Anti-Exfil adds another layer of security by forcing the device to include random data in signatures, preventing attackers from slowly guessing your private keys. With ECDSA (the digital signature algorithm used in Bitcoin), a random private key is combined with a nonce, which is a one-time value intended to add randomness to the signature to ultimately produce a transaction signature that can be validated by other users’ Bitcoin full nodes. Anyone can guess your private key based on your signatures without this random nonce, which is as bad as it sounds! Compromised hardware wallets could create a nonce that appears random but is not. The nonces could be known to an attacker ahead of time. Even worse, the hardware wallet could leak parts of the user’s master private key into individual nonces, which would allow the attacker to guess every private key given a sufficient number of signatures. Anti-Exfil uses “sign-to-contract” to ask Jade to use its signature nonce while cryptographically committing to some random data proposed by the (assumed uncompromised) host computer. The random data’s hash is then combined with the signature nonce to produce the signature. By use of this protocol, the nonce is re-randomized, thus preventing the attack. More info: 10% off on Blockstream store products with coupon "maximus". And the code JADEPLUSEXPRESS gets anyone free expedited shipping on a Jade Plus

Maximus Maximalistus

28,668 Aufrufe • vor 1 Monat

UPDATE: New Zealanders deserve the chance to decide in a democratic way if we stay in the WHO or not. Not the Cabinet behind closed doors. You, me, all of us should decide. That is why I am calling for a referendum. We now have two ways that people can support this campaign: 1) Electronic Parliamentary Petition; 2) Citizens Initiated Referendum Petition. (Links in the comments) Anyone can sign the Electronic Parliamentary Petition. However, the Citizens Initiated Referendum Petition can only be signed by people on the NZ electoral roll and it’s old school – by law you have to sign with a pen and on the paper form. We need signatures from 10% of all registered voters. That’s about 400,000 signatures. It’s a huge number – about equal to every person in Wellington City times two. However, 4000 people collecting 100 signatures, 10,000 collecting 40 signatures or 40,000 collecting 10 signatures gets us to the threshold for a referendum. This is truly a grassroots effort – from the ground up, powered by ordinary Kiwis. We don’t have corporate sponsors. We don’t have taxpayer funding. In fact, under referendum rules, we’re not allowed to spend more than $50,000 on promoting and gathering signatures. However, other groups can spend up to $50,000 promoting the Citizen Initiated Referendum Petition as long as they don’t work with us. If we gather enough signatures, Parliament has to notice. It’s your voice in action: by gathering enough support we can make Parliament debate and act, giving everyday New Zealanders a say in our future. Together, we can show the world what a determined group of Kiwis can do. They may have the World Health Organization, but we have each other – and that is stronger. NZ and the MRNA NZDSOS - NZ Doctors Speaking Out with Science James Lindsay, anti-Communist Peter A. McCullough, MD, MPH® Lee Donoghue Aly Cook Coronavirus Plushie Cam Slater Dr. David Martin Elon Musk Jim Ferguson James Roguski Matt Shelton Perth Today 🇦🇺 Malcolm Roberts 🇦🇺

Kirsten Murfitt

25,115 Aufrufe • vor 1 Jahr

BITCOIN RAILS #69: ZERO-KNOWLEDGE PROOFS FOR POST-QUANTUM BITCOIN | with Benedikt Bünz 🔗 YOUTUBE: 🌿 SPOTIFY: While many Bitcoiners remain hopeful the network will embrace zero-knowledge proofs for protocol-level use cases, practical adoption has remained limited outside of BitVM and a handful of experimental proposals. Most of the world’s ZKP research has circled around Ethereum and other ecosystems, where significant resources have been dedicated to advancing these systems, particularly for scaling and privacy applications. One of the most notable contributors to this research is Benedikt Bünz ☕️ — professor of cryptography at NYU and collaborator of Dan Boneh, who together inarguably form one of the strongest blockchain-applied cryptography teams in the world. The pair recently announced they’ll be leading the new post-quantum cryptography unit localhost research — the first dedicated PQ research effort within a major Bitcoin development organization. With Benedikt leading the charge on the use of zero-knowledge proofs for post-quantum mitigation, the question emerges: will the post-quantum transition be the catalyst to finally bring zero-knowledge proofs to Bitcoin's core protocol? In more detail, Benedikt and I discuss: - Why ZKPs haven’t been widely adopted by the Bitcoin technical community — and why the threat of quantum computers may change that posture going forward - How ZKPs could be used for signature batching to address larger post-quantum signatures in Bitcoin’s post-quantum era - Why Bitcoiners will likely prioritize hash-based signatures as an initial post-quantum scheme — rather than more efficient but less proven alternatives (e.g., lattice-based) - How ZKPs have evolved over the last decade and may finally be ready for Bitcoin’s strict requirements around trust assumptions - Why Benedikt and Dan are teaming up with localhost research to create the first post-quantum cryptography unit within a major Bitcoin development organization + what they hope to accomplish This episode of Bitcoin Rails is brought to you by: LayerTwo Labs LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on Sui — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 00:00 — Intro 00:22 — Benedikt's background 04:10 — How Benedikt got into Bitcoin and cryptography 07:42 — First ZK project: proving exchange solvency after Mt. Gox 16:01 — ZK proofs explained 27:43 — How security gets popular & ZK proofs in Bitcoin 35:49 — Other applications of ZK proofs for Bitcoin 40:15 — Why ZK proofs haven't been adopted in Bitcoin 50:46 — Why the Bitcoin post-quantum transition needs ZK proofs 01:07:00 — Cryptographic agility and why lattices win 01:18:00 — The size problem and how SNARKs solve it 01:33:57 — Proving a Bitcoin block in a laptop in 1.5 seconds 01:37:12 — Bitcoin as the primary quantum target 01:40:47 — ZK proofs for seed phrase recovery

Isabel Foxen Duke⚡️

19,872 Aufrufe • vor 2 Monaten