If you generated a wallet using Libbitcoin's Bitcoin Explorer, including as described in the appendix to Mastering Bitcoin, your funds are at risk (or already stolen).
Full details: https://t.co/Crlw63lUr4
Next version of Bouncy Castle will also include CRYSTALS-Kyber, CRYSTALS-Dilithium, Falcon, and other algorithms! It is available as beta right now at https://t.co/eCO9dydNrV 🎉. A great way to experiment (with care!) with the schemes being standardized by NIST.
In this preprint, in order to counter the Castryck-Decru attack (and derivatives), we suggest to use a fixed degree, but then mask only the torsion point information. How do we do that and why is this worth exploring? A thread! 1/n
It works!!
Here's a @sagemath implementation of the SIDH Key Recovery attack of Castryck and Decru.
Huge thanks to @oudomphe. Their insights allowed us to directly compute the image of points in the Jacobian through divisors. No Gröbner needed!
https://t.co/yzBrTGP4sr
Congratulations to @meshcollider , who successfully defended his PhD thesis "Key Exchange and Zero-Knowledge Proofs from Isogenies and Hyperelliptic Curves" this morning.
@BenWestgate_@RobertSpigler @RideTheBTC @JWWeatherman_@heavilyarmedc I'm not sure this is something that will be *in* Core itself. Especially the sharing part. You can still kinda manually do this with Core right now - use shares to reconstruct a master seed, validate the checksum, then drop the checksum and import the seed with sethdseed RPC.
Successful twitter musig2 signing 🎉🚀
Musig2 is a cool protocol published (CRYPTO'21) by @n1ckler, @real_or_random, and Yannick Seurin.
It lets multiple parties combine their keys and sign messages/transactions with a single signature - indistinguishable from a single signer!