ct seems to me something a bit difficult to obtain trought soft fork, how can a legacy client is supposed to react to a redacted amount?

I think CISA could be more interesting as a base to make every spend a coinjoin and create incentive to mix everyone you can, disrupting eurisptics

Reply to this note

Please Login to reply.

Discussion

i don't know the name of the proposal

it just makes it so the spend address cannot be known ahead of time, it doesn't hide the amounts

I don't think there will ever be monero style hidden amount CTs because of the auditability problem, but being able to prevent attackers from knowing what address spending to monitor for is a big advance for privacy

Oh do you mean MW (mimblewimble) then? It was added to Litecoin as an "extension block" (like a sidechain) and they call it MWEB for MimbleWimble Extension Block

In Litecoin's case they implemented it with CT so it hides amounts but it can be done just as a "mixing" protocol

Bitcoin should just add optional MWEB. A turnstile going back to the transparent side would still guarantee supply.