-
m-relay<kayabanerve:matrix.org> chaser: Not without adding a hash.
-
m-relay<kayabanerve:matrix.org> Eh. A switch commitment could work?
-
m-relay<kayabanerve:matrix.org> If we decide a PQ scheme now, we could embed a PQ KEM into a switch commitment. In the future, a public registry of PQ keys could exist and it'd be verifiable as belonging to the address.
-
m-relay<kayabanerve:matrix.org> But it'd require making a bad decision now a public registry in the future
-
m-relay<chaserene:matrix.org> thanks. deciding on the PQ scheme now sounds unrealistic for sure. and do I understand correctly that the public registry would require some liveness from the owner of the address, which isn't guaranteed to be the case?
-
m-relay<chaserene:matrix.org> in the case of adding a hash, what would you hash?
-
midipoetHow many legit PQ candidate schemes are there at the moment?
-
midipoetWIKI says there are 7.
-
midipoetWith 8 alternate schemes.
-
midipoet
-
midipoet
-
m-relay<chaserene:matrix.org> we only need signature algorithms (last column). of the many finalists, three were selected as winners / standardization targets (en.wikipedia.org/wiki/NIST_Post-Qua…ardization#Selected_Algorithms_2022). in "Zero-cost post-quantum mitigations for Seraphis" (gist.github.com/tevador/23a84444df2…7f1a#5-post-quantum-signature-algor<clipped message>
-
m-relay<chaserene:matrix.org> ithms), tevador outlined that Falcon is patented, which leaves Sphincs+ and Crystals-Dilithium