<oembed><type>rich</type><version>1.0</version><author_name>npub17fjkngg0s0mfx4uhhz6n4puhflwvrhn2h5c78vdr5xda4mvqx89swntr0s</author_name><author_url>https://nostr.ae/npub17fjkngg0s0mfx4uhhz6n4puhflwvrhn2h5c78vdr5xda4mvqx89swntr0s</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2019-12-17&#xA;📝 Original message:&#xA;Thanks a lot David for the suggestion and pointers, that&#39;s a really&#xA;interesting solution.&#xA;I will dive into that in-depth, it could be very useful for many layer-2&#xA;constructions.&#xA;&#xA;Thanks ZmnSCPxj as well for the quick feedback and the `OP_CAT`&#xA;construction,&#xA;a lot of cool tricks coming up once (if?) we have such tools in the future&#xA;;)&#xA;&#xA;Le mar. 17 déc. 2019 à 16:14, ZmnSCPxj &lt;ZmnSCPxj at protonmail.com&gt; a écrit :&#xA;&#xA;&gt; Good morning David, t-bast, and all,&#xA;&gt;&#xA;&gt;&#xA;&gt; &gt; I&#39;m not aware of any way to currently force single-show signatures in&#xA;&gt; &gt; Bitcoin, so this is pretty theoretical. Also, single-show signatures&#xA;&gt; &gt; add a lot of fragility to any setup and make useful features like RBF&#xA;&gt; &gt; fee bumping unavailable.&#xA;&gt;&#xA;&gt; With `OP_CAT`, we can enforce that a particular `R` is used, which allows&#xA;&gt; to implement single-show signatures.&#xA;&gt;&#xA;&gt;     # Assuming signatures are the concatenation of (R,s)&#xA;&gt;     &lt;R&gt; OP_SWAP OP_CAT &lt;ACINQ&gt; OP_CHECKSIG&#xA;&gt;&#xA;&gt; The above would then feed `s` only on the witness stack.&#xA;&gt;&#xA;&gt; Regards,&#xA;&gt; ZmnSCPxj&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/lightning-dev/attachments/20191217/b717706a/attachment.html&gt;</html></oembed>