Replying to Avatar waxwing

Gave a presentation last week on "purecoin", showing basically how ~ 50% embedding rate in "pure" bitcoin transactions with no scripts is inevitable *even if* you force the outputs to prove they are not "fake". 'Fraid the audience had no idea what I was talking about, so I'll post the pdf here:

https://files.catbox.moe/tpfc4x.pdf

I must apologize for calling it a "very hard fork" because you could actually do it as a soft fork (thanks nostr:nprofile1qqsw79gu0guq7s98t473fyavx3akwaafmx6l5z4rehd50lrcl2mf4zcprfmhxue69uhkzer4d36zuvfcwpk82uewwdhkx6tpdshsz9mhwden5te0v96xcctn9ehx7um5wghxcctwvshsz9thwden5te0wfjkccte9ejxzmt4wvhxjme094u090 ) but it's hardly relevant. The point is that there is no version of Bitcoin, even a 99% crippled version of it that doesn't allow L2s, that does not allow data embedding, *except* one in which we completely change the cryptography to BLS (any deterministic signature scheme could in theory do it, but nobody is going to seriously suggest hash-based signatures or RSA FDH I think) (thanks nostr:nprofile1qqsrtnjl8xtejc4k7h38gz6akjv0v75vrsdhlznu0slr2n3tatf8w3qpzpmhxue69uhkummnw3ezumt0d5hs64xj85 for thoughts on this), *and* totally cripple any programmability. And since quantum is coming (so they tell me!) I see basically no chance of this happening.

#bitcoin #cryptography

The link isn't working for me, but does it have anything to do with answering the question below?

nostr:nevent1qqsqqqqpjwnvgh8npetwtxa6sgyj3paf2xg5yypnk8j694fczkt9xngpr9mhxw309ucnjdpwxyun2t3jxgezudph8g6rsdpc9uq3qamnwvaz7tmp9ehx7uewd3hkctcpz4mhxue69uhkg6t5w3hjuur4vghhyetvv9us7faxya

Reply to this note

Please Login to reply.

Discussion

It works for me!

I think the site is blocked in certain countries like UK.

I should have hosted it on github but tbh there's only a few slides, it only helps a little. Basic ideas already on the bitcoin mailing list "on (in)ability to embed data in Schnorr from a few weeks ago.

Wtf is wrong with the uk

How long do you have?

Re: your true or false question: i think the answer might be: technically it's surprisingly false, but it requires almost absurd total redesign of bitcoin; see our discussion here:

nostr:nevent1qqsguqm3e9t4ygt5djz7hcem6l2gxqv056fjr7f0mz5sp560w3xyrhspz4mhxue69uhkummnw3ezummcw3ezuer9wchsygp4ee0nn9uev2m0tcn5pdwmfx8k02xpcxml3f78c034fc4745nhgspsgqqqqqqsvchk7r

And indeed: amount field represents an especially big challenge to prevent embedding, but to be fair it is small and could be smaller. I considered it but keys/signatures are the crucial part.