<oembed><type>rich</type><version>1.0</version><author_name>npub1xz8q68hmzur6c6uje593nscy3q4njx05h4vnxmz2wxxptx7u7casl2925u</author_name><author_url>https://nostr.ae/npub1xz8q68hmzur6c6uje593nscy3q4njx05h4vnxmz2wxxptx7u7casl2925u</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2011-08-24&#xA;🗒️ Summary of this message: Discussion on the use of multi-signature transactions for secure Bitcoin wallets, including the possibility of new Bitcoin addresses and opcodes.&#xA;📝 Original message:On Wed, Aug 24, 2011 at 8:45 AM, Gregory Maxwell &lt;gmaxwell at gmail.com&gt; wrote:&#xA;&#xA;&gt; On Wed, Aug 24, 2011 at 11:12 AM, Gavin Andresen&#xA;&gt; &lt;gavinandresen at gmail.com&gt; wrote:&#xA;&gt; &gt; It seems to me the fastest path to very secure, very-hard-to-lose&#xA;&gt; &gt; bitcoin wallets is multi-signature transactions.&#xA;&gt; &gt;&#xA;&gt; &gt; To organize this discussion: first, does everybody agree?&#xA;&gt;&#xA;&gt; It&#39;s a good tool which we should have in our tool-belt.&#xA;&gt;&#xA;&gt; Though it&#39;s a bit of when you are a hammer all problems are nails.&#xA;&gt; This issue can also be addressed by things like external private key&#xA;&gt; protectors.  But someone would have to build one.&#xA;&gt;&#xA;&gt; Someone might be more inclined to build such a thing if the software&#xA;&gt; had good support for tracking public keys without private keys, and&#xA;&gt; generating unsigned transactions for export to the device for signing.&#xA;&gt;&#xA;&gt; &gt; ByteCoin pointed to a research paper that gives a scheme for splitting&#xA;&gt; &gt; a private key between two people, neither of which every knows the&#xA;&gt; [snip]&#xA;&gt; &gt; So I&#39;m assuming that is NOT the fastest way to solving the problem.&#xA;&gt;&#xA;&gt; Regardless, it might be useful to contact the authors.&#xA;&gt;&#xA;&gt; &gt; I still think it is a good idea to enable a set of new &#39;standard&#39;&#xA;&gt; &gt; multisignature transactions, so they get relayed and included into&#xA;&gt; &gt; blocks.  I don&#39;t want to let &#34;the perfect become the enemy of the&#xA;&gt; &gt; good&#34; -- does anybody disagree?&#xA;&gt;&#xA;&gt; I agree.&#xA;&gt;&#xA;&gt; &gt; The arguments against are that if the proposed standard transactions&#xA;&gt; &gt; are accepted, then the next step is to define a new kind of bitcoin&#xA;&gt; &gt; address that lets coins be deposited into a multisignature-protected&#xA;&gt; &gt; wallet.&#xA;&gt; &gt;&#xA;&gt; &gt; And those new as-yet-undefined bitcoin addresses will have to be 2 or&#xA;&gt; &gt; 3 times as big as current bitcoin addresses, and will be incompatible&#xA;&gt; &gt; with old clients.&#xA;&gt; &gt;&#xA;&gt; &gt; So, if we are going to have new releases that are incompatible with&#xA;&gt; &gt; old clients why not do things right in the first place, implement or&#xA;&gt; &gt; enable opcodes so the new bitcoin addresses can be small, and schedule&#xA;&gt; &gt; a block chain split for N months from now.&#xA;&gt;&#xA;&gt; One way of doing this would be to have an address which hashes an&#xA;&gt; ordered concatenation of many addresses (perhaps plus a length&#xA;&gt; argument). To redeem you provide the public keys which are signing,&#xA;&gt; plus the addresses which aren&#39;t signing, and the receiver validates.&#xA;&gt;&#xA;&gt; If it can be done, then yes, I agree it would be worth forking the chain.&#xA;&gt;&#xA;&gt; This _feels_ like something which could and should be done with the&#xA;&gt; existing (but disabled opcodes).&#xA;&gt;&#xA;&gt;&#xA;&gt; It&#39;s not exclusive, however, with a long N-address address type for&#xA;&gt; multisig destinations.  We could support that _now_ and defer the&#xA;&gt; &#39;compressed version&#39; until after people have experience with this&#xA;&gt; usage.  The only cost would be supporting this address type forever,&#xA;&gt; which isn&#39;t that bad.&#xA;&gt;&#xA;&gt; It&#39;s also important to note that incompatibility wouldn&#39;t be complete:&#xA;&gt; The only limit is that old clients couldn&#39;t send funds to escrow&#xA;&gt; addresses— which is an issue no matter how you encode the information.&#xA;&gt;&#xA;&gt;&#xA;&gt; ------------------------------------------------------------------------------&#xA;&gt; EMC VNX: the world&#39;s simplest storage, starting under $10K&#xA;&gt; The only unified storage solution that offers unified management&#xA;&gt; Up to 160% more powerful than alternatives and 25% more efficient.&#xA;&gt; Guaranteed. http://p.sf.net/sfu/emc-vnx-dev2dev&#xA;&gt; _______________________________________________&#xA;&gt; Bitcoin-development mailing list&#xA;&gt; Bitcoin-development at lists.sourceforge.net&#xA;&gt; https://lists.sourceforge.net/lists/listinfo/bitcoin-development&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20110824/4805602a/attachment.html&gt;</html></oembed>