Replying to Avatar kalle

Just read the disclosure of a severe vulnerability in libbitcoin's `bx` tool that limits seed entropy to 32 bits.

https://milksad.info/disclosure.html

Got me wondering about security of various multi/threshold signature wallets.

Traditional OP_CHECKMULTISIG adds one bit of entropy for each extra signer, given that the individual pubkeys are disclosed. A 2of2 multisig would be 33 bits of entropy and also easily identifiable as vulnerable once a spending tx is published.

But using taproot and musig2, the individual pubkeys are not disclosed, so the number of bits is doubled for each extra sig. A 2of2 multisig would be 64 bits of entropy, and not easily identifiable as vulnerable.

Amirite? nostr:npub1j5mp526z5fkz9wkrk6mt5nzu43xndyrwkr8mnqngdqwytgcpc5vqcnsd5c nostr:npub1vadcfln4ugt2h9ruwsuwu5vu5am4xaka7pw6m7axy79aqyhp6u5q9knuu7

Haven't thought about musig2 this way before. It's a belts and suspenders type of thing in case entropy turns out to suck.

mpc gang layup?

nostr:nprofile1qqsvak4cr0jzaarahhn98a9602e94sa2xt8u9dnjac8cns86lzp0z0spz3mhxue69uhhyetvv9ujuerpd46hxtnfduq3vamnwvaz7tmjv4kxz7fwdehhxarj9e3xzmnyqyxhwumn8ghj7mn0wvhxcmmvaktsf8 @npub1mxrssnzg8y9zjr6a9g6xqwhxfa23xlvmftluakxqatsrp6ez9gjssu0htc

Reply to this note

Please Login to reply.

Discussion

No replies yet.