11:44:58 "pocketchange is 10-out" <- 10 outputs + your normal output + change from your normal output…. So 12 11:45:50 And 11 if you spend an entire output 12:25:50 For 2-output transactions where one is to a subaddress and the second one is the change, only one tx public key is used (r * subaddress's view key). The footnote in ZtM says it's to blend in with other 2-out txs. But doesn't this mean the receiver can tell that the second output is change? Since if it weren't change, then there would be two public keys, one for each output 12:55:17 MasFlam[m]1: the probability a 2-out tx does not have change is very very low 20:49:38 MasFlam: Yes. It assumes there's always a change output, as sufficiently sane.