#tlsnotary-chat

/

      • proslogion has quit
      • belcher has quit
      • BB-Martino has quit
      • BB-Martino joined the channel
      • proslogion joined the channel
      • proslogion
        waxwing: does the non-interactive coinjoin still require everyone to sign the same tx hash?
      • waxwing
        proslogion: what do you mean by non-interactive, specifically?
      • proslogion
        not really at least in the case of BLS, the OWAS is a set of different signatures on different messages
      • not sure what's the case for Schnorr
      • MrMoneyBags joined the channel
      • waxwing
        proslogion: i asked "what do you mean by X?" and your answer was "not really". :)
      • proslogion
        OWAS means "one way aggregate signature"
      • waxwing: sorry dunno how to phrase it
      • because it's what supposedly can be done with Schnorr but actually can't
      • waxwing
        proslogion: before understanding everything else, i was hoping you'd answer what you meant by "non-interactive coinjoin".
      • now i read again, i guess you just ignored the question and continued your own conversation, it's fine :)
      • proslogion
        waxwing: i dunno, gmaxwell used that phrase here: https://bitcointalk.org/index.php?topic=1377298.0
      • i have to read Horas Yuan Mouton's paper to find out what it may be
      • waxwing
        yes, so in the case of schnorr as laid out by sipa anyway, there is an interactivity step, yeah
      • the BLS thing i started to look at but then dropped, it's going to be hard to say the least, to understand it
      • proslogion
        waxwing: well, i meant, supposedly Schnorr doesn't have that flaw
      • i struggle to understand how non-interactivity can be achieved
      • in that case
      • waxwing
        i would have thought if it could be done, they would be implementing it that way, not the 2-round multisignature thing that's in alpha
      • re: the thread you linked yesterday, i thought this message was a really interesting read: https://bitcointalk.org/index.php?topic=1427885...
      • proslogion
        yeah, but that's because of the flaw i think, if supposedly the flaw doesn't exist, i still don't see how you could get non-interactivity with Schnorr
      • like the original "just merge the pubkey" recipe
      • waxwing
        you mean the pubkey subtraction flaw?
      • proslogion
        yeah
      • waxwing: right that was a very good summary
      • waxwing
        yeah it's a pretty interesting question really. might take another look at it.
      • MrMoneyBags has quit
      • proslogion has quit
      • proslogion joined the channel
      • BB-Martino has quit
      • BB-Martino joined the channel
      • proslogion has quit
      • proslogion joined the channel
      • proslogion has quit
      • belcher joined the channel
      • belcher has quit