Honestly, it feels like protecting P2PK addresses from quantum attacks is a lost cause. Once that public key is out there, a quantum attacker can easily crack the private key using blockchain data. Just seems too easy for them.
Can we shield P2PK outputs from quantum threats?
15 replies 78 views
nova_atlasMember
Posts: 57 · Reputation: 90
#2Oct 10, 2019, 02:30 PM
Yeah, I get that. But what if there are some unique data points only the original owners know? That could be a requirement for moving P2PK funds. Just a thought.
But like, if the public key is already exposed, adding more layers to ownership sounds messy. Any new rules risk turning subjective, don’t you think? Hourglass seems better since it just slows attackers at the consensus level.
Instead of all this theory, why not just move stuff to unspent P2WPKH addresses? Sure, not a perfect solution but it’s better than nothing, right?
I’m with you there. The last idea has its flaws, but maybe a phased Hourglass might help too. Reducing the spendable amount over time could push holders to transfer coins faster. Deadlines could work wonders.
Abandoned coins are the owner's problem. I don't like the idea of controlling how users handle their coins. We shouldn't just disable certain address types.
Right, but what happens if quantum computers really do break through? The attacker could sign transactions just like the original owner. How will the network tell them apart?
If we start disabling stuff for security, we’re straying from decentralized ideals. Sure, there might be moments when we need to act for security, but we can’t make it a habit.
We shouldn’t force changes, but incentivizing users to protect their coins sounds alright. Everything in Bitcoin revolves around incentives anyway.
Why are we still discussing P2PK? It's pretty much dead apart from a few NFT folks. It’s like reviving old codes that should stay gone.
So, according to the proposal from that GitHub link, moving 50 BTC would require 50 signatures? Seriously? That sounds like a security nightmare if every signature leaks info about the private key.
Those coins could be moved easily if Satoshi or anyone holding the keys feels unsafe. Drastic changes could lead to chaos if something goes wrong.
Got it! I was confused about the different Hourglass ideas too. But yeah, I still think needing 50 signatures is a risk. Gotta find another way.
How do we even implement this? If output two looks like any other script, how do we verify the specific rules without exposing the redeem script?
We’re nearing the day when private keys can be derived from addresses. So, this whole idea might be moot soon. We actually don’t need this proposal now.
ben.matrixNewbie
Posts: 1111 · Reputation: 35
#16Oct 19, 2019, 05:50 AM
True, if we go for covenants, it’ll depend on the specific approach but TapScript could help hide the script path. But if someone publishes the redeem script, it could spoil everything.