https://github.com/kayabaNerve/fcmp-ringct/blob/develop/fcmp%2B%2B.pdf
New paper from some Monero researchers (really new it seems - update date is last week!), in which they're proposing to use CurveTrees (the same construct I put into aut-ct as per my recent work) to get much larger anonymity sets (and I do mean *much larger*, from like 10ish to 100000000!).
One very notable thing (to me) is that the very easy and natural secp/secq 2-cycle (you realistically need a 2 cycle of curves for CurveTrees), has to be replaced with something more complex, because their DJB ed25519 curve has a cofactor of 8 (yet again non prime order curve biting them on the ass, lol).
Another interesting tidbit is that they propose to use Liam Eagan's recent work https://eprint.iacr.org/2022/596 (posted almost contemporaneously with Curve Trees); I remember Andrew Poelstra pointing me at this work in '22 and I said to him "I don't understand this" and he responded "yeah it was difficult so I got Liam to come round to my house and explain it" 😁 .. so yeah i'm sure some people can follow the ideas there but I am alas not yet one of them :)
They've also done a review of the generalized bulletproofs construction that Kamp et al used in their CurveTrees implementation: https://github.com/cypherstack/generalized-bulletproofs
Also interesting is that they talk about acheiving a "forward secrecy" property here, which linkable ring signatures can't have, by design: if a future ECDL breaker is found, it can always see the trace of payments in prior Monero because the linking tag reveals the private key if you can crack ECDLP. I'm not sure how this works but I believe it's to do with the Liam Eagan research just mentioned.
Finally, the extremely esoteric and dense mathematical concepts aside, it's worth mention a 1000 ft view: this proposal ditches ring signatures (and somehow they get backwards compatibility for the historical chain, though I absolutely don't understand that yet), and goes to a full ZKP proving system (bulletproofs arithmetic circuits) for full anon set. I can't help wondering if this direction makes sense - if we look at Zcash, they do the same thing, but using bilinear pairings they can get far more performant proof, proof size and verification stats, I believe (but, curvetrees can be very efficient so I'm not 100% sure about the details here). Ring sigs, as I've observed elsewhere, even with the fanciest algorithms, never quite cut it at the verification step to be able to support huge anonymity sets. If you're going to ditch them, you may just as well go with a Zcash style design, no?
heard so many good things about zcash system, id be immensely incredible to bring the tech to thriving monero ecosystem
i remember the premiere being shown on #hcpp23 and also cody's story told irl...
it was very strong.
after incredible !223 days! of uptime, you deserve some rest and maintainance!
you've been a good and free monero & bitcoin node, a matrix bot, http backend and so much more.
there are people who don't feel negative connotation to the word "proprietary", they even like it
probably not at first ask.
but in my experience if you are a long customer in for example a coffee shop, as you get to know the owner you might slip some crypto talk into it and eventually maybe get them interested in receiving at as a payment.
it has to be careful and gradual.
wallets should normalise embedding neutrino based fullnodes into mobile wallets, so that you dont sacrifice privacy to random electrum nodes
schnorr's cross input key aggregation is THE solution to bitcoin scalability and privacy
every transaction is an unobservable coinjoin, which solves privacy and also merges many txs into one.
not possible yet currently, but im hopeful for a bright and not too distant future
fuck man i love eliptic curve, just learnt about the inner workings
its so beautiful yet simple
its business. u wouldnt understand
tbh its impressive to me how stable the bitcoind is. haven't had it crash in a few months.
however the monerod crashes once in a two weeks maybe
bitcoin needs to get inspired more by monero and less by shit saylorfuck says
mainstream adoption is the enemy
look what they did to youtube and the internet
ui is just graphic way to edit json
tbh i vibe more w/ kendrick.
i like drake with melodies, hate drake when he act tough
u know u can just lie there, right
the funny thing about refusing cookies is that the cookie consent keeps showing up after each page reload
debating monero vs bitcoin is retarded
love and enjoy both.
two rival gangs in berlin
eingang vs ausgang
lots of people on the ausgang side
