-
plowsof[m]Given a private viewkey/main wallet address - can i tell if a subadress came from that wallet?
-
UkoeHByes, if you can guess the subaddress index
-
Rucknium[m]1The main topic of the next MRL meeting on Wednesday will be the fee policy and dynamic block size:
-
Rucknium[m]1
-
ScalabilityThanks Rucknium[m]1.
-
UkoeHBArticMine[m]: monero-project/research-lab #70#issuecomment-1024964432
-
jberman[m]UkoeHB: do you think there is any chance that in the future 120 bit security will be deemed unsafe before 128 bit security?
-
jberman[m]like is that probability so close to 0 that it's not worth considering to you
-
jberman[m]or if anyone has an informed answer to that, would be interested to hear
-
jberman[m]is it irrational to build 128 bit security systems when we can in some cases build slightly more performant 120 bit systems instead
-
jberman[m]if the answer is nebulous, then better to err on the side of caution imo
-
UkoeHBSecurity levels are kind of 'ballpark'. I think 120 bits falls into the k=128 zone of influence... so to speak.
-
jberman[m]Aumasson also has an interesting paper discussing this I'm reading it now: eprint.iacr.org/2019/1492.pdf
-
jberman[m]I'm pretty convinced. vtnerd jtgrassie what do y'all think
-
jberman[m]convinced 120 bits is ok
-
mj-xmr[m]My January dev report:
-
mj-xmr[m]
-
UkoeHBnothing there
-
plowsof[m]Appears to be an empty thread for me
-
jberman[m]UkoeHB: tevador also brought up a good point that a hash function is still necessary to decouple view tags of outputs directed to the same wallet within the same transaction. that + veorq's last comment seem to leave us with cn_fast_hash, no?
-
mj-xmr[m]<plowsof[m]> "Appears to be an empty thread..." <- Hmm. Perhaps it needs a moderator's tick. Let's wait and see then.
-
mj-xmr[m]Thanks plowsof. That outta do it :)
-
UkoeHBjberman[m]: Ah yes, we need the output index. I am getting rid of that requirement in Seraphis.
-
jberman[m]gah, debate over. finally
-
jberman[m]woohoo :D
-
UkoeHB?
-
UkoeHBSiphash is also a hash function?
-
jberman[m]> In general you shouldn’t take the (encoded) point as a symmetric key
-
jberman[m]directly, as shared secret; it should be hashed to whatever key length you
-
jberman[m]need. I assumed the 128 bits were the hashed point.
-
jberman[m]veorq's last comment
-
dangerousfreedomHello guys,... (full message at libera.ems.host/_matrix/media/r0/do…b9c58413f0049328262c035a4d1e5486bc2)