15:34:34 Given a private viewkey/main wallet address - can i tell if a subadress came from that wallet? 15:39:53 yes, if you can guess the subaddress index 18:16:05 The main topic of the next MRL meeting on Wednesday will be the fee policy and dynamic block size: 18:16:05 https://github.com/monero-project/meta/issues/657 18:16:45 Thanks Rucknium[m]1. 18:39:32 ArticMine[m]: https://github.com/monero-project/research-lab/issues/70#issuecomment-1024964432 20:27:01 UkoeHB: do you think there is any chance that in the future 120 bit security will be deemed unsafe before 128 bit security? 20:27:46 like is that probability so close to 0 that it's not worth considering to you 20:32:46 or if anyone has an informed answer to that, would be interested to hear 20:33:53 is it irrational to build 128 bit security systems when we can in some cases build slightly more performant 120 bit systems instead 20:35:02 if the answer is nebulous, then better to err on the side of caution imo 20:47:56 Security levels are kind of 'ballpark'. I think 120 bits falls into the k=128 zone of influence... so to speak. 20:52:31 Aumasson also has an interesting paper discussing this I'm reading it now: https://eprint.iacr.org/2019/1492.pdf 21:04:46 I'm pretty convinced. vtnerd jtgrassie what do y'all think 21:06:46 convinced 120 bits is ok 21:34:43 My January dev report: 21:34:43 https://www.reddit.com/r/Monero/comments/sfs195/mjs_dev_report_2022_jan/ 21:37:00 nothing there 21:37:17 Appears to be an empty thread for me 21:46:45 UkoeHB: tevador also brought up a good point that a hash function is still necessary to decouple view tags of outputs directed to the same wallet within the same transaction. that + veorq's last comment seem to leave us with cn_fast_hash, no? 21:47:13 "Appears to be an empty thread..." <- Hmm. Perhaps it needs a moderator's tick. Let's wait and see then. 21:48:38 Thanks plowsof. That outta do it :) 21:54:09 jberman[m]: Ah yes, we need the output index. I am getting rid of that requirement in Seraphis. 21:54:52 gah, debate over. finally 21:55:01 woohoo :D 21:55:02 ? 21:55:28 Siphash is also a hash function? 21:55:52 > In general you shouldn’t take the (encoded) point as a symmetric key 21:55:52 directly, as shared secret; it should be hashed to whatever key length you 21:55:52 need. I assumed the 128 bits were the hashed point. 21:55:56 veorq's last comment 22:57:28 Hello guys,... (full message at https://libera.ems.host/_matrix/media/r0/download/libera.chat/423dcb9c58413f0049328262c035a4d1e5486bc2)