sipa changed the topic of #bitcoin-wizards to: This channel is for discussing theoretical ideas with regard to cryptocurrencies, not about short-term Bitcoin development | http://bitcoin.ninja/ | This channel is logged. | For logs and more information, visit http://bitcoin.ninja
Leo_Verto1 has quit []
CryptoDavid has quit [Quit: Connection closed for inactivity]
son0p has quit [Ping timeout: 240 seconds]
mreider has joined #bitcoin-wizards
Kiminuo has quit [Ping timeout: 250 seconds]
son0p has joined #bitcoin-wizards
ZmnSCPxj has joined #bitcoin-wizards
<ZmnSCPxj>
If I needed a blind signing scheme for bearer signatures, what would be best and why? Also it seems Schnorr blind signing is vulnerable to Wagner attacks, can anyone point to some convenient treatise on such?
<ZmnSCPxj>
thank you, thus you would suggest the use of Schnorr blind signing, suitably modified as per this paper?
<sipa>
i'm probably not the best person to ask, but it sounds like that paper gives a pretty convincing argument that with that modification they're actually secure
<sipa>
using AGM in the proof is unusual, but imho it's not a crazy model
ZmnSCPxj has quit [Quit: ZmnSCPxj]
ZmnSCPxj has joined #bitcoin-wizards
AaronvanW has quit [Remote host closed the connection]
TheoStorm has quit [Quit: Leaving]
<ZmnSCPxj>
I observe that Wasabi claims to use Schnorr blind signing to implement bearer signatures, I have not seen their actual code or checked their protocol in detail however.
marcoagner has quit [Ping timeout: 276 seconds]
<ZmnSCPxj>
My understanding of the above paper, is essentially the client and (signing) server, run two signing sessions in parallel, but the server provides `s` for only one and drops the other, is that a fair restatement?
<sipa>
I haven't actually read the paper.
AaronvanW has joined #bitcoin-wizards
<gmaxwell>
just doing two is likely not enough.
<gmaxwell>
you only need a couple parallel sessions to really reduce the security a lot, so you could just guess which one the servers goingt choose and get it right with reasonable odds.
<gmaxwell>
like say you need only 4 parallel signatures to get to 2^64 attack work... well you've got 1:16 chance to just guess which ones the server will pick.
AaronvanW has quit [Ping timeout: 250 seconds]
<ZmnSCPxj>
I see.
<gmaxwell>
so I think to defend against a 4-way attack you'll want something like 128/4 signatures per signature.
<ZmnSCPxj>
32 sub-sessions per single produced blinded signature?
<ZmnSCPxj>
Or 2^32?
son0p has quit [Ping timeout: 276 seconds]
<ZmnSCPxj>
I believe I have seen text before which suggests andytoshi was conjecturing that 128 sub-sessions per single produced blinded signature would be enough.
son0p has joined #bitcoin-wizards
son0p has quit [Quit: leaving]
AaronvanW has joined #bitcoin-wizards
<gmaxwell>
ah ignore my bad math, 128 per does make more sense. you really want (say) (1/n)^4 to be ~= 1/2^128
<ZmnSCPxj>
128 == 2^7, and 128^4 is only 2^28. Maybe it considers the added work *on top of* the 2^64 work as well?
bsm1175321 has quit [Quit: Leaving.]
AaronvanW has quit [Ping timeout: 265 seconds]
llfourn has joined #bitcoin-wizards
mreider has quit []
slivera_ has joined #bitcoin-wizards
alferz has joined #bitcoin-wizards
alferz has quit [Ping timeout: 240 seconds]
alezandro has joined #bitcoin-wizards
rusty has quit [Quit: Leaving.]
davterra has quit [Quit: Leaving]
Bjarki has joined #bitcoin-wizards
Belkaar has quit [Ping timeout: 250 seconds]
Belkaar has joined #bitcoin-wizards
Belkaar has joined #bitcoin-wizards
Belkaar has quit [Changing host]
llfourn has quit [Ping timeout: 250 seconds]
AaronvanW has joined #bitcoin-wizards
davterra has joined #bitcoin-wizards
llfourn has joined #bitcoin-wizards
rusty has joined #bitcoin-wizards
AaronvanW has quit [Ping timeout: 276 seconds]
Bjarki has quit []
brianhoffman_ has joined #bitcoin-wizards
brianhoffman has quit [Ping timeout: 250 seconds]
brianhoffman_ is now known as brianhoffman
llfourn has quit [Ping timeout: 240 seconds]
DougieBot5000 has quit [Ping timeout: 265 seconds]
csharpsteen has joined #bitcoin-wizards
slivera_ has quit [Quit: Leaving]
DougieBot5000 has joined #bitcoin-wizards
slivera has joined #bitcoin-wizards
AaronvanW has joined #bitcoin-wizards
AaronvanW has quit [Ping timeout: 246 seconds]
AaronvanW has joined #bitcoin-wizards
designwi- has quit [Ping timeout: 240 seconds]
designwish has joined #bitcoin-wizards
Kiminuo has joined #bitcoin-wizards
csharpsteen has quit []
queip has joined #bitcoin-wizards
belcher has quit [Ping timeout: 265 seconds]
kanzure has quit [Ping timeout: 246 seconds]
kanzure has joined #bitcoin-wizards
gribble has quit [Read error: Connection reset by peer]
belcher has joined #bitcoin-wizards
gribble has joined #bitcoin-wizards
AaronvanW has quit [Remote host closed the connection]
AaronvanW has joined #bitcoin-wizards
Guyver2 has joined #bitcoin-wizards
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
<nickler>
By my own estimation for 120+ bits of security the number of parallel sessions should be around 512 (but I did that was before the paper was published, perhaps they arrive at more accurate numbers) https://gist.github.com/jonasnick/28836e8754870d938ea838cd2323bdd8
slivera has quit [Remote host closed the connection]
<nickler>
Afaik Wasabi uses the naive, Wagnerable version but they're saying forgery would not allow for more than DoS-ing a round.
Alphi has joined #bitcoin-wizards
Apocalyptic has joined #bitcoin-wizards
queip has quit [Ping timeout: 276 seconds]
queip has joined #bitcoin-wizards
rusty has quit [Quit: Leaving.]
queip has quit [Ping timeout: 245 seconds]
queip has joined #bitcoin-wizards
jonatack has quit [Ping timeout: 245 seconds]
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
bildramer has quit [Remote host closed the connection]
bildramer has joined #bitcoin-wizards
Kiminuo has quit [Ping timeout: 250 seconds]
rusty has joined #bitcoin-wizards
marcoagner has joined #bitcoin-wizards
queip has quit [Ping timeout: 265 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 246 seconds]
queip has joined #bitcoin-wizards
slivera has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
TheoStorm has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
Chris_Stewart_5 has joined #bitcoin-wizards
queip has joined #bitcoin-wizards
slivera has quit [Remote host closed the connection]
queip has quit [Ping timeout: 268 seconds]
jonatack has joined #bitcoin-wizards
queip has joined #bitcoin-wizards
Alphi has quit []
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 276 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
queip_ has joined #bitcoin-wizards
queip has quit [Ping timeout: 268 seconds]
queip_ is now known as queip
queip has quit [Ping timeout: 250 seconds]
queip has joined #bitcoin-wizards
tromp_ has joined #bitcoin-wizards
queip has quit [Ping timeout: 246 seconds]
Chris_Stewart_5 has quit [Ping timeout: 240 seconds]
tromp has quit [Ping timeout: 276 seconds]
beaups1 has joined #bitcoin-wizards
queip has joined #bitcoin-wizards
Chris_Stewart_5 has joined #bitcoin-wizards
TheoStorm has quit [Remote host closed the connection]
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
ZmnSCPxj has quit [Remote host closed the connection]
ZmnSCPxj has joined #bitcoin-wizards
queip has quit [Ping timeout: 250 seconds]
queip has joined #bitcoin-wizards
jonatack has quit [Ping timeout: 240 seconds]
lowentropy has quit [Ping timeout: 260 seconds]
lowentropy has joined #bitcoin-wizards
queip has quit [Ping timeout: 252 seconds]
queip has joined #bitcoin-wizards
son0p has joined #bitcoin-wizards
queip has quit [Ping timeout: 265 seconds]
Kiminuo has joined #bitcoin-wizards
queip has joined #bitcoin-wizards
andytoshi has joined #bitcoin-wizards
andytoshi has joined #bitcoin-wizards
andytoshi has quit [Changing host]
son0p has quit [Ping timeout: 240 seconds]
spinza has quit [Ping timeout: 265 seconds]
roconnor has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
son0p has joined #bitcoin-wizards
belcher has quit [Quit: Leaving]
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 265 seconds]
Kiminuo has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
jonatack has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
beaups1 has quit []
belcher has joined #bitcoin-wizards
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 250 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
setpill has joined #bitcoin-wizards
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
jnewbery has quit [Read error: Connection reset by peer]
jnewbery has joined #bitcoin-wizards
doitux|mob has joined #bitcoin-wizards
mdunnio has joined #bitcoin-wizards
jnewbery has quit [Read error: Connection reset by peer]
jnewbery has joined #bitcoin-wizards
jonatack has quit [Read error: Connection reset by peer]
davterra has quit [Quit: Leaving]
jnewbery has quit [Read error: Connection reset by peer]
jnewbery has joined #bitcoin-wizards
queip has quit [Ping timeout: 265 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
spinza has joined #bitcoin-wizards
queip has quit [Ping timeout: 245 seconds]
queip has joined #bitcoin-wizards
ddustin has joined #bitcoin-wizards
ddustin has quit [Ping timeout: 268 seconds]
jonatack has joined #bitcoin-wizards
Krellan has quit [Remote host closed the connection]
Krellan has joined #bitcoin-wizards
setpill has quit [Quit: o/]
Krellan has quit [Ping timeout: 245 seconds]
son0p has quit [Ping timeout: 268 seconds]
queip has quit [Ping timeout: 252 seconds]
queip has joined #bitcoin-wizards
AaronvanW has quit [Remote host closed the connection]
AaronvanW has joined #bitcoin-wizards
queip has quit [Ping timeout: 265 seconds]
queip has joined #bitcoin-wizards
AaronvanW has quit [Remote host closed the connection]
queip has quit [Ping timeout: 265 seconds]
queip has joined #bitcoin-wizards
alezandro has quit [Ping timeout: 250 seconds]
AaronvanW has joined #bitcoin-wizards
alezandro has joined #bitcoin-wizards
AaronvanW has quit [Remote host closed the connection]
AaronvanW has joined #bitcoin-wizards
doitux|mob has quit []
Krellan has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 268 seconds]
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
mackr has joined #bitcoin-wizards
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
jtimon has joined #bitcoin-wizards
mdunnio has quit [Remote host closed the connection]
queip has quit [Ping timeout: 265 seconds]
mdunnio has joined #bitcoin-wizards
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 268 seconds]
queip has joined #bitcoin-wizards
Krellan has joined #bitcoin-wizards
queip has quit [Ping timeout: 268 seconds]
mdunnio has quit [Remote host closed the connection]
mdunnio has joined #bitcoin-wizards
queip has joined #bitcoin-wizards
jonatack has quit [Ping timeout: 276 seconds]
jonatack has joined #bitcoin-wizards
Chris_Stewart_5 has quit [Ping timeout: 268 seconds]
queip has quit [Ping timeout: 240 seconds]
queip has joined #bitcoin-wizards
queip has quit [Ping timeout: 265 seconds]
queip has joined #bitcoin-wizards
phwalkr has joined #bitcoin-wizards
queip has quit [Ping timeout: 268 seconds]
jonatack has quit [Ping timeout: 252 seconds]
jonatack has joined #bitcoin-wizards
mdunnio has quit [Remote host closed the connection]
mdunnio has joined #bitcoin-wizards
phwalkr has quit [Remote host closed the connection]
mdunnio has quit [Remote host closed the connection]
mdunnio has joined #bitcoin-wizards
Krellan has quit [Ping timeout: 250 seconds]
slivera has joined #bitcoin-wizards
Aaronvan_ has joined #bitcoin-wizards
AaronvanW has quit [Ping timeout: 246 seconds]
Aaronvan_ is now known as AaronvanW
mackr has quit []
mdunnio has quit [Remote host closed the connection]
mdunnio has joined #bitcoin-wizards
SLot has joined #bitcoin-wizards
rusty has quit [Quit: Leaving.]
Krellan has joined #bitcoin-wizards
Guyver2 has quit [Quit: Going offline, see ya! (www.adiirc.com)]
Krellan has quit [Ping timeout: 245 seconds]
Chris_Stewart_5 has joined #bitcoin-wizards
Kiminuo has joined #bitcoin-wizards
morcos has quit [Remote host closed the connection]
slivera has quit [Remote host closed the connection]
slivera has joined #bitcoin-wizards
Kiminuo has quit [Ping timeout: 268 seconds]
morcos has joined #bitcoin-wizards
paultroon_ has joined #bitcoin-wizards
paultroon has quit [Read error: Connection reset by peer]
achow101_ has joined #bitcoin-wizards
achow101 has quit [Read error: Connection reset by peer]
json_18 has quit [Quit: Ping timeout (120 seconds)]