-
kayabanerve[m]When Monero becomes PQ, if I was to comment right now how we should, I'd simply suggest using a STARK for every single component. It'll be incredibly slower, but it avoids a lot of security/composability issues. There's still no PQ lift for the DLP :/
-
kayabanerve[m]But a STARK can prove a SHA-256 preimage and a 32-byte SHA can be equivalent to a n-item Pedersen commitment so...