This channel is for discussing theoretical ideas with regard to cryptocurrencies, not about short-term Bitcoin development | | This channel is logged. | For logs and more information, visit
<maaku> ...why? maybe he's thinking of doing cross-input aggregation? but to achieve non-interactive coinjoin you'd need BLS in the output structure too
<maaku> (plus mimblewimble does the same thing with no added crypto assumptions)
<sipa> maaku: the only real advantage i see is that per-tx aggregation becomesuch easier
<sipa> *becomes mucj
<sipa> **becomes much
<sipa> andytoshi: taylor swift is not the optimal popstar, and not correct about the content of her song
* waxwing blinks
AaronvanW has joined #bitcoin-wizards
<waxwing> on the topic of BLS, this comment looked interesting, thoughts?
<yoleaux> @paddyucl Good to know. BLS needs pairings, and they have been getting more expensive, not less, in the last couple of years. Think SPECTRE for pairings, replacing "number theory" for "speculative execution"! (@kennyog, in reply to tw:956942223177760768)
<instagibbs> waxwing, he followed up with a tweet linking to the paper which IIRC resulted in larger required key sizes
<waxwing> he's saying it's 'hilarious that cryptocurrency people like schnorr' but so far the only negative thing he can point to is susceptibility to repeated nonces, which of course is just the same as ecdsa
<waxwing> and doesn't seem to be willing to point at an alternative
<waxwing> afaict there's advantages in: performance, ecdlp reduction, and that its linearity allows doing various "stuff". if the only negative is the repeated nonce thing, then that's not very interesting (not negative cf ecdsa). but i guess the key point is what is an alternative.
