Can Bitcoin Integrate Ring Signatures?

8 replies 256 views
Posts: 67 · Reputation: 87
#1Oct 29, 2019, 07:41 PM
Been chatting about this in another thread and I'm curious. How would we actually bring Ring Signatures into Bitcoin? I'm not really a dev, but here's my take. It's gotta involve some changes at the Protocol and Consensus layers. 1. New opcodes would be essential, right? Probably a soft fork needed. 2. Inputs would have to point to multiple UTXOs since only one is really spent. Sounds complicated.
4 Reply Quote Share
paulmaxiSenior Member
Posts: 2 · Reputation: 868
#2Oct 31, 2019, 08:38 PM
Adding Ring Signatures could boost privacy big time. But just to clarify, it wouldn’t hide old transactions, only new ones. And yeah, this needs a ton of effort and planning.
3 Reply Quote Share
dave.apeMember
Posts: 2 · Reputation: 218
#3Nov 1, 2019, 12:34 AM
I’m no expert, but this feels like it could take ages. Just thinking about how exchanges and KYC would deal with “dirty” coins is wild. They’ll have to adapt or get stuck.
2 Reply Quote Share
ColdGangMember
Posts: 57 · Reputation: 183
#4Nov 2, 2019, 10:16 AM
For real, adding ring signatures might be a huge overhaul. We might mess with Bitcoin’s core mechanics on how transactions link to funds. Plus, wallets would need a serious revamp. But let’s be real, it could slow things down and hike up costs. And preventing double-spending with this new method? Total headache. Old coins would stay unchanged, so it’s really just for new stuff.
4 Reply Quote Share
Posts: 7 · Reputation: 237
#5Nov 2, 2019, 03:02 PM
Yeah, basic ring signatures eat up space based on ring size, which is not great. Newer designs are better since they keep sizes logarithmic, but the real issue is UTXO size. You can’t tell the real input from the decoys, so UTXO sets would explode. Monero gets away with it kinda because their transaction volume is way lower than Bitcoin's.
3 Reply Quote Share
alexsatNewbie
Posts: 110 · Reputation: 15
#6Nov 2, 2019, 04:03 PM
Is this even doable without a hard fork? I mean, how would old nodes handle these transactions? If they see multiple inputs, they could assume all are spent. Gotta think there would be a new input format similar to Segwit, but this could be a bigger deal.
3 Reply Quote Share
Posts: 67 · Reputation: 87
#7Nov 3, 2019, 11:14 PM
So, you’re saying ring signatures aren’t space-efficient by default? In Monero, it’s set to 16, so 15 decoys and 1 real UTXO. I saw that PR about a double fork, but I need to dig deeper into it. It’ll be tough with older nodes, so yeah, a new address format makes sense.
6 Reply Quote Share
alex.byteLegendary
Posts: 70 · Reputation: 5910
#8Nov 5, 2019, 02:25 PM
You could build it on Taproot, right? One Taproot address could serve multiple users at once. This is how other coins are doing it. But if it’s optional and just adds costs for ring signature users, the rest of the network might be fine.
4 Reply Quote Share
0xNodeMember
Posts: 257 · Reputation: 80
#9Nov 5, 2019, 05:41 PM
This opens up possibilities for smart contract mixers, kinda like what’s on Ethereum. Super excited for what’s next. But exchanges will still blacklist addresses linked to bad ones, which is a mess. Coinjoins could help, but it seems like eventually, all coins might fall into 'clean' or 'mixed' categories.
3 Reply Quote Share

Related topics