New Proposal for Quantum-Resistance in Bitcoin

20 replies 52 views
RogueGuruNewbie
Posts: 8 · Reputation: 23
#1Oct 31, 2021, 12:02 AM
Saw a new BIP hit the dev mailing list. It’s about making Bitcoin quantum-resistant. I checked the links and found more info on bitcoin.foundation. Thought I’d share this here, see what people think.
3 Reply Quote Share
alexsatNewbie
Posts: 280 · Reputation: 15
#2Oct 31, 2021, 05:05 AM
This BIP looks similar to Lopp's idea about phasing out ECDSA in a few years. But seriously, do we trust the Bitcoin Foundation? Seems sketchy to me.
3 Reply Quote Share
RogueGuruNewbie
Posts: 8 · Reputation: 23
#3Oct 31, 2021, 06:54 AM
I disagree, not the same as Lopp’s BIP. Bitcoin Foundation's ownership doesn't make it untrustworthy. Domains like bitcoin.org are owned by others too. Seems like jealousy to me.
1 Reply Quote Share
gang2015Member
Posts: 690 · Reputation: 62
#4Oct 31, 2021, 09:08 AM
I just skimmed through but I’m not a fan. For one, zero references in the BIP itself. Plus, SPHINCS+ signatures are huge. How will that not slow down transactions?
3 Reply Quote Share
RogueGuruNewbie
Posts: 8 · Reputation: 23
#5Oct 31, 2021, 09:27 AM
I noticed they mentioned SegWit v3. Looking at the code, max block size is capped at 4 MB. I don’t get why it can’t go higher, like 2 GB. Not sure we’d ever fill that.
2 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#6Oct 31, 2021, 02:55 PM
Could be a valid point but non-upgraded nodes shouldn’t handle all that data. No need to bump the block size specifically; just set a limit on quantum signatures.
1 Reply Quote Share
alexsatNewbie
Posts: 280 · Reputation: 15
#7Oct 31, 2021, 11:55 PM
You been around during the 2017 debates? Bigger blocks = big issues. Sure, let’s just throw in 2 GB blocks! SegWit adjustments are minor. SPHINCS+ is tough, not every quantum crypto will hold up.
0 Reply Quote Share
chris23Member
Posts: 45 · Reputation: 44
#8Nov 1, 2021, 06:12 AM
For the record, bitcoin.foundation isn’t the original Bitcoin Foundation, which died off years ago. The owner has a shady history of domains.
3 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#9Nov 2, 2021, 04:04 PM
Good thing legacy nodes are 1 MB and SegWit is 4 MB. If you want over 4 MB, those nodes won’t see the data. Quantum signatures should stay separate from old nodes.
3 Reply Quote Share
gang2015Member
Posts: 690 · Reputation: 62
#10Nov 3, 2021, 12:10 AM
They don't clarify how to prevent bloat. Just like SegWit, SPHINCS+ will still be massive and won’t help with blockchain bloat.
1 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#11Nov 4, 2021, 08:13 AM
But only the upgraded nodes deal with the bloat. Legacy users stick to 4 MB. If quantum security turns out to be a hoax, those new nodes will still have their bloated chains.
3 Reply Quote Share
gang2015Member
Posts: 690 · Reputation: 62
#12Nov 4, 2021, 02:16 PM
Yeah, but blocks with quantum signatures show support for upgrades. Non-SegWit nodes still deal with Ordinal TXs, just without the extra data.
3 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#13Nov 5, 2021, 02:25 PM
Existing miners don’t need to support this. They can stick to what’s familiar with ECDSA. If their miners do more work, they could confirm faster.
3 Reply Quote Share
RogueGuruNewbie
Posts: 8 · Reputation: 23
#14Nov 5, 2021, 05:36 PM
I might’ve missed it. Can you lay it out? How do you go from 50 kB to 50 bytes?
5 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#15Nov 5, 2021, 11:03 PM
And how do you upgrade from 1 MB to 4 MB? SegWit uses 32 bytes for commitments. Just like that, we can store larger quantum signatures behind the current structure.
0 Reply Quote Share
RogueGuruNewbie
Posts: 8 · Reputation: 23
#16Nov 6, 2021, 05:07 AM
ECDSA and R-values? I think we need a bigger block size. 4 MB won’t cut it only a few SPHINCS+ transactions fit in there when today we have a ton.
3 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#17Nov 6, 2021, 07:38 AM
Same way quantum signatures can be hidden. Old ECDSA signatures could still verify as long as the commitments are intact. Legacy nodes won’t get it.
0 Reply Quote Share
RogueGuruNewbie
Posts: 8 · Reputation: 23
#18Nov 6, 2021, 11:46 PM
Interesting take! But why even mix quantum-resistant hashing with ECDSA? If ECDSA is toast, you’re done for regardless.
2 Reply Quote Share
alex.byteLegendary
Posts: 182 · Reputation: 5910
#19Nov 7, 2021, 04:34 AM
Not many non-SegWit nodes left anyway. Soon, we might not have to worry about them and just cut them off.
3 Reply Quote Share
Posts: 3540 · Reputation: 35
#20Nov 7, 2021, 09:29 AM
Why not? ECDSA still works. If it fails, we can block it like we do with P2TR keys. If quantum signatures fail too, we can downgrade later.
2 Reply Quote Share

Related topics