--- Day changed Sat Feb 01 2020 00:47 -!- dr-orlovsky [~dr-orlovs@77-58-192-184.dclient.hispeed.ch] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…] 01:34 -!- Jackielove4u [uid43977@gateway/web/irccloud.com/x-dwmudwlvkzbbulmk] has joined ##taproot-bip-review 02:25 -!- ghost43 [~daer@gateway/tor-sasl/daer] has quit [Remote host closed the connection] 02:26 -!- ghost43 [~daer@gateway/tor-sasl/daer] has joined ##taproot-bip-review 06:22 -!- ghost43 [~daer@gateway/tor-sasl/daer] has quit [Remote host closed the connection] 06:22 -!- ghost43 [~daer@gateway/tor-sasl/daer] has joined ##taproot-bip-review 07:13 -!- pinheadmz [~matthewzi@195.181.168.216] has quit [Read error: Connection reset by peer] 07:13 -!- pinheadmz_ [~matthewzi@pool-100-33-69-78.nycmny.fios.verizon.net] has joined ##taproot-bip-review 08:03 -!- felixweis [sid154231@gateway/web/irccloud.com/x-dwybcsuvqtnhdgjd] has quit [] 08:03 -!- felixweis [sid154231@gateway/web/irccloud.com/x-vqmefdkkwyinjdil] has joined ##taproot-bip-review 08:19 < waxwing> hmm not *all* the protection of key prefixing are lost with attacker controlled input. but .. the ones you care about are, that much seems clear :) 08:20 < waxwing> (was just thinking about the case of multiplicative tweak: take existing s with key P and pretend it's on key P' = (e1/e0)P ... but seems like an 'attack' of little relevance in practice) 08:21 < waxwing> additive tweak though, yeah 08:22 < waxwing> do we really need such optimizations? 08:33 < sipa> waxwing: i wouldn't say it's accomodating an optimization, it's prevent complete key leakage in case someone inevitably does anyway :) 08:40 -!- elichai2 [sid212594@gateway/web/irccloud.com/x-comdeojcshxsgfje] has quit [] 08:41 -!- elichai2 [sid212594@gateway/web/irccloud.com/x-cncrzmpnfvrebfez] has joined ##taproot-bip-review 08:41 < waxwing> ok, good point. and i guess that's the high level take away from what gmaxwell was saying in the ml post .. inputs to k must be inputs to signing algo (at least), which with key prefixing, includes P. 08:43 < waxwing> so basically nonce gen fn input should include the temperature in Addis Ababa because people might decide that that's an appropriate input to signing too :) 08:53 < sipa> i assume you're joking, but i don't see it 08:55 < waxwing> yeah it doesn't quite work like that, since the actual stuff inside the challenge hash is what you have to match up, not just .. any input someone might dream up for their signing algo 08:58 < waxwing> there is a broader concept (or joke) relevant to all these fiat shamir transform based things, which is how difficult is to figure out what is the proper context that has to be explicitly fixed vs what is implicit (like .. generator of the curve for example :) ) 08:58 -!- jeremyrubin [~jr@c-67-180-60-249.hsd1.ca.comcast.net] has quit [Quit: Konversation terminated!] 09:30 -!- sipa [~pw@gateway/tor-sasl/sipa1024] has quit [Remote host closed the connection] 09:41 -!- sipa [~pw@gateway/tor-sasl/sipa1024] has joined ##taproot-bip-review 10:34 -!- pglazman [~pglazman@38.104.224.174] has joined ##taproot-bip-review 10:40 -!- pinheadmz_ [~matthewzi@pool-100-33-69-78.nycmny.fios.verizon.net] has quit [Quit: pinheadmz_] 10:50 -!- pglazman [~pglazman@38.104.224.174] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…] 10:51 -!- pglazman [~pglazman@38.104.224.174] has joined ##taproot-bip-review 10:53 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has joined ##taproot-bip-review 11:13 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has quit [Quit: notmandatory] 11:56 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has joined ##taproot-bip-review 12:21 -!- pglazman [~pglazman@38.104.224.174] has quit [Quit: My MacBook has gone to sleep. ZZZzzz…] 12:27 -!- ghost43 [~daer@gateway/tor-sasl/daer] has quit [Remote host closed the connection] 12:28 -!- ghost43 [~daer@gateway/tor-sasl/daer] has joined ##taproot-bip-review 12:37 -!- pglazman [~pglazman@38.104.224.174] has joined ##taproot-bip-review 12:38 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has quit [Quit: notmandatory] 12:40 -!- pglazman [~pglazman@38.104.224.174] has quit [Client Quit] 13:13 -!- pglazman [~pglazman@38.104.224.174] has joined ##taproot-bip-review 13:13 -!- pglazman [~pglazman@38.104.224.174] has quit [Client Quit] 13:38 -!- pglazman [~pglazman@38.104.224.174] has joined ##taproot-bip-review 13:38 -!- pglazman [~pglazman@38.104.224.174] has quit [Client Quit] 13:42 -!- pglazman [~pglazman@67.23.55.162] has joined ##taproot-bip-review 13:47 -!- pglazman [~pglazman@67.23.55.162] has quit [Ping timeout: 260 seconds] 13:57 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has joined ##taproot-bip-review 14:33 -!- belcher [~belcher@unaffiliated/belcher] has quit [Ping timeout: 268 seconds] 15:44 -!- belcher [~belcher@unaffiliated/belcher] has joined ##taproot-bip-review 15:49 -!- belcher [~belcher@unaffiliated/belcher] has quit [Ping timeout: 265 seconds] 16:22 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has quit [Quit: notmandatory] 16:27 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has joined ##taproot-bip-review 16:51 -!- belcher [~belcher@unaffiliated/belcher] has joined ##taproot-bip-review 17:37 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has quit [Quit: notmandatory] 17:58 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has joined ##taproot-bip-review 18:06 -!- belcher [~belcher@unaffiliated/belcher] has quit [Quit: Leaving] 18:12 -!- notmandatory [~textual@cpe-76-169-37-102.socal.res.rr.com] has quit [Quit: notmandatory] 18:59 -!- pinheadmz [~matthewzi@pool-100-33-69-78.nycmny.fios.verizon.net] has joined ##taproot-bip-review 19:04 -!- achow101 [~achow101@unaffiliated/achow101] has quit [Ping timeout: 268 seconds] 19:45 -!- achow101 [~achow101@unaffiliated/achow101] has joined ##taproot-bip-review 20:41 < aj> sipa: the temperature in addis ababa could be the rng for the synthetic nonce? 20:51 < gmaxwell> sounds like blockchain.info 20:52 < gmaxwell> k = `curl random.org/404page`