-
gingeropolouswhats the size of an ringsize equivalent triptych tx? i keep losing that image with the graphs
-
gingeropolousoh its in the paper sweet
-
gingeropolouswell kindaq
-
sarangWhat do you mean "size of ringsize equivalent" gingeropolous
-
gingeropolousringsize 11 ,
-
sarangOh you'd need to use ringsize 16 or some other exponent decomposition
-
tevadorAFAIK triptych is log-size, the limiting factor is verification performance, not proof size
-
sarangcorrect
-
saranggingeropolous: for `N=16` a CLSAG signature would be 576 bytes, while a Triptych proof would be 640 bytes
-
sarangSizes for other transaction elements (keys, linking tag, range proof, auxiliary data) would not change
-
sarangFor multi-input transactions you add additional signatures/proofs to accommodate
-
gingeropolousroight roight
-
sarangSo how's research today?
-
sarangI'm rewriting a CLSAG proof :)
-
rbrunnerSo after the info from Turtle Coin's IBurnMyCD I copied some code from here to try: github.com/turtlecoin/cs-turtlecoin…master/CantiLib/Cryptography/Native
-
rbrunnerResult: Works perfectly. Starting with a private key, I get everything else, the view key and both public keys.
-
rbrunnerSo whatever this does, and does differently than the packages that I tried so far, being a more or less direct port of the Monero C++ code, this does "the right thing"
-
moneromoooToo bad adding more code for MS' trojan is not "the right thing" though.
-
rbrunnerIt will run on .NET core, on a Linux server. The whole C# stuff is still Microsoft of course however.
-
rbrunnerAnd for what it's worth, the C# compiler and the .NET framework are open source. Microsoft even switched to Git internally a while ago.
-
» moneromooo winces
-
rbrunnerWhy so?
-
rbrunnerMaybe time to switch to #monero :)
-
sarangAnyone feel like reading over a security proof before I send it off to the CLSAG auditors for their comments?
-
sarangThey suggested expanding on the proof of Theorem 1 from the preprint, which I've done in much more detail
-
sarangUpdated proof of CLSAG Theorem 1: usercontent.irccloud-cdn.com/file/karoRzRt/proof-theorem-1.pdf
-
sarangThe only change of note is that in the first part of the proof, there are an extra `q` signing oracle queries