Transitioning Bitcoin to Quantum-Resistant Standards

21 replies 257 views
Posts: 172 · Reputation: 24
#1Oct 3, 2017, 07:36 AM
There’s a new BIP draft in the air, aimed at boosting Bitcoin’s security against quantum threats. Authors include some familiar names like Lopp, Papathanasiou, and others. They’re proposing a shift to a quantum-resistant crypto standard with a three-phase rollout.
6 Reply Quote Share
alex.byteLegendary
Posts: 170 · Reputation: 5910
#2Oct 3, 2017, 10:20 AM
So the idea is to scrap ECDSA and Schnorr signatures and adopt P2QRH outputs instead. But I'm thinking... should we just make old output types non-standard instead of outright invalidating them? I feel like that could cause chaos.
3 Reply Quote Share
0x4lphaFull Member
Posts: 519 · Reputation: 509
#3Oct 4, 2017, 08:26 PM
Totally agree. We can still send coins to some weird formats right now. If we go all out on disabling old types, we'd essentially kill Script, and that’s kinda drastic.
2 Reply Quote Share
danmoonNewbie
Posts: 19 · Reputation: 29
#4Oct 4, 2017, 09:20 PM
Not sure about P2QRH tbh. I mean, aren't those signatures gonna be huge? Current ones are already a pain with mempool space.
2 Reply Quote Share
Posts: 1 · Reputation: 4
#5Oct 5, 2017, 01:34 AM
Exactly, if the size jumps up, we're looking at some serious mempool congestion. SPHINCS+ signatures are like 70k bytes, right? Imagine the bottleneck.
2 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#6Oct 5, 2017, 03:37 AM
Yeah, the signature size is a real concern. P2QRH's signatures could balloon to over 7k bytes, that’s nuts! Higher fees and fewer transactions per second? Like going from 7 TPS to less than 1 is a disaster waiting to happen.
6 Reply Quote Share
alex.byteLegendary
Posts: 170 · Reputation: 5910
#7Oct 5, 2017, 09:53 AM
I feel you, congestion and risks with cold storage could become huge problems. I just don't see the point in keeping vulnerable options around.
5 Reply Quote Share
Posts: 172 · Reputation: 24
#8Oct 5, 2017, 03:05 PM
But if we force everyone to migrate, we’re risking burning coins, especially with a soft-fork approach. Some users won’t even know what hit them if we disable OP_CHECKSIG.
6 Reply Quote Share
WildWolfMember
Posts: 168 · Reputation: 43
#9Oct 5, 2017, 05:38 PM
Right, it’s gonna be a mess if half the Bitcoin community is stuck on old scripts. Those still using legacy outputs would be sitting ducks… not good at all.
1 Reply Quote Share
Posts: 3 · Reputation: 71
#10Oct 5, 2017, 09:41 PM
And what’s the deal with Satoshi’s bitcoins? Some say they’re at risk, but isn’t the threat mostly about actual spending? Like, if they never move, are they really at risk?
4 Reply Quote Share
Posts: 172 · Reputation: 24
#11Oct 6, 2017, 03:43 AM
It’s tricky. Quantum computing could potentially get to your private key if you expose your public key regularly. Like with old P2PK addresses which reveal that straight away.
0 Reply Quote Share
Posts: 172 · Reputation: 24
#12Oct 6, 2017, 07:05 AM
Exactly! Plus, current Segwit addresses only show hashed keys until used. Way safer than older formats. Those early coins are definitely in more danger.
3 Reply Quote Share
gang2015Member
Posts: 682 · Reputation: 62
#13Oct 6, 2017, 01:02 PM
I mean, Lopp is on this BIP and he’s definitely no stranger to the concerns about quantum recovery. His earlier posts hint at a strong stance against letting quantum attacks become a reality.
2 Reply Quote Share
Posts: 172 · Reputation: 24
#14Oct 6, 2017, 01:18 PM
But there are like five other authors too, so it’s not all just him. Still, this feels like we’re between a rock and a hard place. Protect old coins or risk a severe network impact.
1 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#15Oct 6, 2017, 04:00 PM
Some have such wild fears about Satoshi-era coins being stolen, but does anyone actually think that’s a likely scenario? Seems a bit exaggerated to me.
4 Reply Quote Share
alexsatNewbie
Posts: 278 · Reputation: 15
#16Oct 6, 2017, 07:07 PM
Exactly! And even if it did happen, it wouldn’t spell doom for Bitcoin. It would stir some FUD though, that’s for sure.
6 Reply Quote Share
Posts: 172 · Reputation: 24
#17Oct 6, 2017, 07:59 PM
I think everyone’s being a bit dramatic. It’s not a total game-over situation. We just need to adapt, it’s all part of evolution.
5 Reply Quote Share
gang2015Member
Posts: 682 · Reputation: 62
#18Oct 7, 2017, 12:39 AM
100% disagree with mandatory PQ cryptography from phase A. We gotta balance risk and usability. Let’s educate users instead of freezing UTXOs.
3 Reply Quote Share
ben2019Newbie
Posts: 21 · Reputation: 37
#19Oct 7, 2017, 01:01 AM
True, the Satoshi stash might serve as a warning sign. Any breach could spark huge concern, but it’s years away still.
2 Reply Quote Share
0xNodeMember
Posts: 671 · Reputation: 80
#20Oct 7, 2017, 05:26 AM
For sure, but if they start freezing coins, then where does it end? Gotta look out for the long-term implications here.
1 Reply Quote Share

Related topics