Halseth is making an *actual* proposal for zk channel announcements in LN gossip! :

https://delvingbitcoin.org/t/zk-gossip-for-lightning-channel-announcements/1407/

This topic has fascinated me for the last couple years. LN has a kind of unique position to blaze the trail of creating pure cost based, fully private, anti Sybil/DOS of the type that every privacy network needs.

(Disclaimer: I don't believe PoW works, long term, for anything outside of bitcoin. Probably. )

Reply to this note

Please Login to reply.

Discussion

What’s wrong with PoW?

Specialization, mainly. You want the cost per unit to be fixed for all users.

If the PoW scheme requires the user to commit to some user id in the hash, would that satisfy specialization?

Don't think so? (Also there are no user ids in bitcoin).

Yea, just making sure I understand the problem. I agree in general that pow appears to still be lookin for a second use case.

I was thinking a user id (if one exists) would make a pow at least only useable for one user.

Very interesting, and there is PoC already! Thanks for sharing :)

As you can see here:

https://github.com/halseth/output-zero/issues/10#issuecomment-2633912441

proving time without gpu acceleration is no good as of yet (15 mins on my kinda normal laptop). Let's see if optimization brings it down a ton.

Aut-ct proving times are 1-2 seconds. I think curve trees are a better solution for this, but it is extremely debatable.

nostr:nevent1qqsp5h40zj6drc9un2r3agmxv3lgr0yfjcf8lgpqtj22fn6dvu9pkqgpz9mhxue69uhkummnw3ezuamfdejj7q3qvadcfln4ugt2h9ruwsuwu5vu5am4xaka7pw6m7axy79aqyhp6u5qxpqqqqqqzmmtr4p