Billy Tetrud [ARCHIVE] on Nostr: 📅 Original date posted:2022-02-25 📝 Original message:> El Gamal commitments, ...
📅 Original date posted:2022-02-25
📝 Original message:> El Gamal commitments, for example, are perfectly binding but only
computationally hiding.
That's very interesting. I stand corrected in that respect. Thanks for the
information Adam!
On Fri, Feb 25, 2022, 05:17 AdamISZ <AdamISZ at protonmail.com> wrote:
> > I really don't see a world where bitcoin goes that route. Hiding coin
> amounts would make it impossible to audit the blockchain and verify that
> there hasn't been inflation and the emission schedule is on schedule. It
> would inherently remove unconditional soundness from bitcoin and replace it
> with computational soundness. Even if bitcoin did adopt it, it would keep
> backwards compatibility with old style addresses which could continue to
> use ordinals.
>
> Nit: it isn't technically correct to say that amount hiding "inherently
> removes unconditional soundness". Such commitments can be either perfectly
> hiding or perfectly binding; it isn't even logically possible for them to
> be both, sadly. But we are not forced to choose perfect binding; El Gamal
> commitments, for example, are perfectly binding but only computationally
> hiding.
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220225/8c71070c/attachment-0001.html>
📝 Original message:> El Gamal commitments, for example, are perfectly binding but only
computationally hiding.
That's very interesting. I stand corrected in that respect. Thanks for the
information Adam!
On Fri, Feb 25, 2022, 05:17 AdamISZ <AdamISZ at protonmail.com> wrote:
> > I really don't see a world where bitcoin goes that route. Hiding coin
> amounts would make it impossible to audit the blockchain and verify that
> there hasn't been inflation and the emission schedule is on schedule. It
> would inherently remove unconditional soundness from bitcoin and replace it
> with computational soundness. Even if bitcoin did adopt it, it would keep
> backwards compatibility with old style addresses which could continue to
> use ordinals.
>
> Nit: it isn't technically correct to say that amount hiding "inherently
> removes unconditional soundness". Such commitments can be either perfectly
> hiding or perfectly binding; it isn't even logically possible for them to
> be both, sadly. But we are not forced to choose perfect binding; El Gamal
> commitments, for example, are perfectly binding but only computationally
> hiding.
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20220225/8c71070c/attachment-0001.html>