<oembed><type>rich</type><version>1.0</version><author_name>npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_name><author_url>https://nostr.ae/npub1s4lj77xuzcu7wy04afcr487f0r3za0f8n2775xrpkld2sv639mjqsd44kw</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2011-08-24&#xA;🗒️ Summary of this message: Multi-signature transactions are the fastest way to secure Bitcoin wallets, but there is debate over implementing new standard transactions and addresses.&#xA;📝 Original message:It seems to me the fastest path to very secure, very-hard-to-lose&#xA;bitcoin wallets is multi-signature transactions.&#xA;&#xA;To organize this discussion: first, does everybody agree?&#xA;&#xA;ByteCoin pointed to a research paper that gives a scheme for splitting&#xA;a private key between two people, neither of which every knows the&#xA;full key, but, together, both can DSA-sign transactions.  That&#39;s very&#xA;cool, but it involves high-end cutting-edge crypto like zero-knowledge&#xA;proofs that I know very little about (are implementations available?&#xA;are they patented?  have they been thoroughly vetted/tested?  etc).&#xA;So I&#39;m assuming that is NOT the fastest way to solving the problem.&#xA;&#xA;If anybody has some open-source, patent-free, thoroughly-tested code&#xA;that already does DSA-key-splitting, speak up please.&#xA;&#xA;&#xA;I&#39;ve been trying to get consensus on low-level &#39;standard&#39; transactions&#xA;for transactions that must be signed by 2 or 3 keys; current draft&#xA;proposal is here:&#xA; https://gist.github.com/39158239e36f6af69d6f&#xA;and discussion on the forums here:&#xA; https://bitcointalk.org/index.php?topic=38928.0&#xA;... and there is a pull request that is relevant here:&#xA; https://github.com/bitcoin/bitcoin/pull/319&#xA;&#xA;&#xA;I still think it is a good idea to enable a set of new &#39;standard&#39;&#xA;multisignature transactions, so they get relayed and included into&#xA;blocks.  I don&#39;t want to let &#34;the perfect become the enemy of the&#xA;good&#34; -- does anybody disagree?&#xA;&#xA;The arguments against are that if the proposed standard transactions&#xA;are accepted, then the next step is to define a new kind of bitcoin&#xA;address that lets coins be deposited into a multisignature-protected&#xA;wallet.&#xA;&#xA;And those new as-yet-undefined bitcoin addresses will have to be 2 or&#xA;3 times as big as current bitcoin addresses, and will be incompatible&#xA;with old clients.&#xA;&#xA;So, if we are going to have new releases that are incompatible with&#xA;old clients why not do things right in the first place, implement or&#xA;enable opcodes so the new bitcoin addresses can be small, and schedule&#xA;a block chain split for N months from now.&#xA;&#xA;My biggest worry is we&#39;ll say &#34;Sure, it&#39;ll only take a couple days to&#xA;agree on how to do it right&#34; and six months from now there is still no&#xA;consensus on exactly which digest function should be used, or whether&#xA;or not there should be a new opcode for arbitrary boolean expressions&#xA;involving keypairs.  And people&#39;s wallets continue to get lost or&#xA;stolen.&#xA;&#xA;&#xA;&#xA;-- &#xA;--&#xA;Gavin Andresen</html></oembed>