<oembed><type>rich</type><version>1.0</version><author_name>npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_name><author_url>https://nostr.ae/npub1m230cem2yh3mtdzkg32qhj73uytgkyg5ylxsu083n3tpjnajxx4qqa2np2</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-01-20&#xA;📝 Original message:On Sat, Jan 18, 2014 at 05:12:58PM -0600, Jeremy Spilman wrote:&#xA;&gt; &#xA;&gt; &#xA;&gt; &gt; On Fri, Jan 17, 2014 at 8:55 PM, Alan Reiner &lt;etotheipi at gmail.com&gt; wrote:&#xA;&gt; &gt;&gt; Isn&#39;t there a much faster asymmetric scheme that we can use?  I&#39;ve heard people talk about ed25519, though I&#39;m not sure it can be used for encryption.&#xA;&gt; &gt; &#xA;&gt; &gt; Doing ECDH with our curve is within a factor of ~2 of the fastest&#xA;&gt; &gt; encryption available at this security level, AFAIK.  And separate&#xA;&gt; &gt; encryption would ~double the amount of data vs using the ephemeral key&#xA;&gt; &gt; for derivation.&#xA;&gt; &gt; &#xA;&gt; &gt; Using another cryptosystem would mandate carry around additional code&#xA;&gt; &gt; for a fast implementation of that cryptosystem, which wouldn&#39;t be&#xA;&gt; &gt; fantastic.&#xA;&gt; &gt; &#xA;&gt; &gt; So I&#39;m not sure much can be improved there.&#xA;&gt; &#xA;&gt; In the case where payment is being sent only to Q1, and Q2 is for discovery only, perhaps we could use a 160-bit curve for d2/Q2 and e/P resulting in 20 byte vs 32 bytes in the OP_RETURN, and of course faster multiplication. &#xA;&gt; &#xA;&gt; 80-bits of security I assume still greatly exceeds the actual level of privacy you get with the overall solution, and since Q2 is never protecting actual funds...&#xA;&gt; &#xA;&gt; But if it&#39;s a &#34;real weakening&#34; of the privacy then definitely not worth it, and even the added complexity of another curve seems possibly not worth it...&#xA;&#xA;Keep in mind that Bitmessage uses the same ECDH mechanism as what&#xA;stealth addresses will use. They seem to get decent enough performance&#xA;from it for a use-case not-unlike that of a Bitcoin wallet.&#xA;&#xA;In any case I&#39;m interested in knowing actual performance numbers for it;&#xA;last I talked to Kyle Drake he said he was working on getting ECDH&#xA;numbers on Javascript, probably the slowest possible implementation of&#xA;the idea. As for send to stealth addresses using prefixes, he&#39;s&#xA;confirmed that you&#39;ll be able to do that will well under a second to&#xA;brute-force the prefixes with the proposed OP_RETURN mechanism even with&#xA;rather long 8-bit prefixes.&#xA;&#xA;-- &#xA;&#39;peter&#39;[:-1]@petertodd.org&#xA;000000000000000190a2900f1a25c507a999fa11116f7bd0126618c1ebc4f5fb&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: signature.asc&#xA;Type: application/pgp-signature&#xA;Size: 685 bytes&#xA;Desc: Digital signature&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140120/69317ce0/attachment.sig&gt;</html></oembed>