What would quantum-safe Nostr look like?

Nostr is actually well-positioned for post-quantum migration:

Possible approaches:

* New NIP for PQC keys

* * Dilithium

* * Falcon

* * SPHINCS+

* Dual-key identities

* * Classical key (secp256k1)

* * PQC key (for forward security)

* Identity rotation

* *Old pubkey signs new PQC pubkey

* Relays enforcing PQC-only events

---

Thanks nostr:npub1jvnpg4c6ljadf5t6ry0w9q0rnm4mksde87kglkrc993z46c39axsgq89sc for making me look into Nostr's quantum resistance and turning my shitpost into a little bit of knowledge and exploration.

I am far from an expert in cryptography, so this could all be bullshit.

Reply to this note

Please Login to reply.

Discussion

You can just talk about post quantum cryptography, apparently 🙃

You can just [talk/be silent] about post quantum cryptography

Schrodinger's nostrich? 😂

All the users Nostr doesn't have are in superposition.

It is an open protocol.

True, you only know once you open it.

Yes. Yes you can.

Just a contextual rib ser!

You already know more than me by making this note 😂

You don't know if a quantum shitpost is serious or not until you observe it.

Yeah it's bullshit. FUD. Call me in another 5-15 years. Or 50. I'll be signing shit with eliptic curves and so will you. Let's not waste time humoring this psyop against the freedom tech that is real and actually works

It's coming eventually, the timeframe is unclear. And wanting freedom technology to be ready so it can continue to be a beacon of hope for billions isn't a psychological operation. It's a reality that big brains will have to deal with at some point.

Travel outside the milkyway is coming too. Timeframe unclear.

Agreed.

Everyone making a mountain from a mole hill.

Quantum resistance is being developed. Once it’s ready the address format should be implemented. Giving optionality.

There’s no financial gain for a quantum attacker to come out of nowhere and steal legacy coins. The same as there’s no financial gain in a 51% attack.

You don't seem to be aware of how damaging adding a quantum option to the network is to the network. It sound like "no big deal, just add an option" when you just say the words, but do you really understand the implications? Centralization? Security? Performance? Complexity? Bugs? These algos are not proven, they are slow and a d bloated and it changes the dynamics of running nodes in major ways.

Here's a post I did a month ago with a brief rundown of some of the impacts it would have on the network.

nostr:nevent1qqs97qhj03szcjc6z25tszlg694a2wzmkaya5ecx2t2qg796hu9tu3szyrzrdrz39ecwxe2clgt8je7dw07g829fql4r3vlddq6clj7l4vx6vqcyqqqqqqgndsahx

On the quantum upgrade part I’m too retarded to understand any of that.

What I do understand and agree with is that the actual quantum computer required for this is near on impossible. I worked that out by riffing with Grok for a couple of hours.

But, near on impossible isn’t impossible so optionality is going to be required going forward

Saying that it is possible is an unproven and unfalsifiable claim. Everyone involved in running the QC circus has huge incentives.

- There are strong reasons to believe that it is NOT possible.

- There are strong reasons to believe that, if it is possible, it may be very far in the future.

- There are strong reasons to believe the people raising the alarm are either being fooled or have strong incentives to raise a false alarm.

- Doing anything about it seriously damages Bitcoin and freedom tech in general

- If they ever actually do crack the first key, we will have plenty of time to adapt before meaningful QC threat is economically viable

- FUD also hurts Bitcoin and freedom tech

Conclusion: Do not touch the code, just shut down FUD to protect freedom

We fight battles like this over and over.

It’s in the same realm as travelling outside the milkyway.

Also, the same as a 51% attack is possible but not economically viable a once off quantum attack is also not economically viable.

Exactly. Anybody can make these kinds of unfalsifiable claims and collect infinite money if they get a hype bubble going

Ah, from your initial post I didn't realize you were a believer.

Respectfully, I disagree.

I've looked into the claim the scientists are making of why they think it "should" be possible. I have looked into their incentives. I have looked into what they are pointing to as progress. (Isolation improvements which don't prove the real question) I have looked into the wall of weasel words they hide behind.

I'm just not buying it. They have not proven "it's coming." Much less when.

If they get to the point of running shor on one real key (which I don't think they will) we will have plenty of time to deal with it before it becomes economically scalable to be a threat.

"But what it there is a secret super quantum computer?" C'mon. That's silly.

If I am wrong and it happens, then we switch to those garbage PQ algos, bloat the crap out of everything we are doing and take the security hit of leaving our battle tested algos behind.

Until then, just say "no" to masking up for quantum covid and taking PQMRNA injection in our tech.

Your followers are already in a quantum state on Nostr 👍

https://v.nostr.build/mtSZqIWHcPlL5kX8.mp4

Thanks Vitor 🤣

Schroedinger's followers

Which of you geniuses told Schödinger to join nostr..

Nostr is already "spooky action at a distance" 😎