Will This Quantum Computing Breakthrough Save Bitcoin and ...

Bitcoin provides instant transaction confirmation because of its quantum properties

submitted by r2d2_21 to programmingcirclejerk [link] [comments]

Bitcoin mentioned around Reddit: Bitcoin provides instant transaction confirmation because of its quantum properties /r/programmingcirclejerk

Bitcoin mentioned around Reddit: Bitcoin provides instant transaction confirmation because of its quantum properties /programmingcirclejerk submitted by HiIAMCaptainObvious to BitcoinAll [link] [comments]

qBitcoin Whitepaper - "employ quantum digital signature so that it naturally inherits properties of peer-to-peer (P2P) cash system as originally proposed in Bitcoin"

submitted by BitcoinAllBot to BitcoinAll [link] [comments]

What mathematical properties make cryptography quantum-proof? /r/Bitcoin

What mathematical properties make cryptography quantum-proof? /Bitcoin submitted by BitcoinAllBot to BitcoinAll [link] [comments]

Bitcoins Accepted by Quantum Properties

Bitcoins Accepted by Quantum Properties submitted by krisscross23 to Bitcoin [link] [comments]

Technical: Taproot: Why Activate?

This is a follow-up on https://old.reddit.com/Bitcoin/comments/hqzp14/technical_the_path_to_taproot_activation/
Taproot! Everybody wants it!! But... you might ask yourself: sure, everybody else wants it, but why would I, sovereign Bitcoin HODLer, want it? Surely I can be better than everybody else because I swapped XXX fiat for Bitcoin unlike all those nocoiners?
And it is important for you to know the reasons why you, o sovereign Bitcoiner, would want Taproot activated. After all, your nodes (or the nodes your wallets use, which if you are SPV, you hopefully can pester to your wallet vendoimplementor about) need to be upgraded in order for Taproot activation to actually succeed instead of becoming a hot sticky mess.
First, let's consider some principles of Bitcoin.
I'm sure most of us here would agree that the above are very important principles of Bitcoin and that these are principles we would not be willing to remove. If anything, we would want those principles strengthened (especially the last one, financial privacy, which current Bitcoin is only sporadically strong with: you can get privacy, it just requires effort to do so).
So, how does Taproot affect those principles?

Taproot and Your /Coins

Most HODLers probably HODL their coins in singlesig addresses. Sadly, switching to Taproot would do very little for you (it gives a mild discount at spend time, at the cost of a mild increase in fee at receive time (paid by whoever sends to you, so if it's a self-send from a P2PKH or bech32 address, you pay for this); mostly a wash).
(technical details: a Taproot output is 1 version byte + 32 byte public key, while a P2WPKH (bech32 singlesig) output is 1 version byte + 20 byte public key hash, so the Taproot output spends 12 bytes more; spending from a P2WPKH requires revealing a 32-byte public key later, which is not needed with Taproot, and Taproot signatures are about 9 bytes smaller than P2WPKH signatures, but the 32 bytes plus 9 bytes is divided by 4 because of the witness discount, so it saves about 11 bytes; mostly a wash, it increases blockweight by about 1 virtual byte, 4 weight for each Taproot-output-input, compared to P2WPKH-output-input).
However, as your HODLings grow in value, you might start wondering if multisignature k-of-n setups might be better for the security of your savings. And it is in multisignature that Taproot starts to give benefits!
Taproot switches to using Schnorr signing scheme. Schnorr makes key aggregation -- constructing a single public key from multiple public keys -- almost as trivial as adding numbers together. "Almost" because it involves some fairly advanced math instead of simple boring number adding, but hey when was the last time you added up your grocery list prices by hand huh?
With current P2SH and P2WSH multisignature schemes, if you have a 2-of-3 setup, then to spend, you need to provide two different signatures from two different public keys. With Taproot, you can create, using special moon math, a single public key that represents your 2-of-3 setup. Then you just put two of your devices together, have them communicate to each other (this can be done airgapped, in theory, by sending QR codes: the software to do this is not even being built yet, but that's because Taproot hasn't activated yet!), and they will make a single signature to authorize any spend from your 2-of-3 address. That's 73 witness bytes -- 18.25 virtual bytes -- of signatures you save!
And if you decide that your current setup with 1-of-1 P2PKH / P2WPKH addresses is just fine as-is: well, that's the whole point of a softfork: backwards-compatibility; you can receive from Taproot users just fine, and once your wallet is updated for Taproot-sending support, you can send to Taproot users just fine as well!
(P2WPKH and P2WSH -- SegWit v0 -- addresses start with bc1q; Taproot -- SegWit v1 --- addresses start with bc1p, in case you wanted to know the difference; in bech32 q is 0, p is 1)
Now how about HODLers who keep all, or some, of their coins on custodial services? Well, any custodial service worth its salt would be doing at least 2-of-3, or probably something even bigger, like 11-of-15. So your custodial service, if it switched to using Taproot internally, could save a lot more (imagine an 11-of-15 getting reduced from 11 signatures to just 1!), which --- we can only hope! --- should translate to lower fees and better customer service from your custodial service!
So I think we can say, very accurately, that the Bitcoin principle --- that YOU are in control of your money --- can only be helped by Taproot (if you are doing multisignature), and, because P2PKH and P2WPKH remain validly-usable addresses in a Taproot future, will not be harmed by Taproot. Its benefit to this principle might be small (it mostly only benefits multisignature users) but since it has no drawbacks with this (i.e. singlesig users can continue to use P2WPKH and P2PKH still) this is still a nice, tidy win!
(even singlesig users get a minor benefit, in that multisig users will now reduce their blockchain space footprint, so that fees can be kept low for everybody; so for example even if you have your single set of private keys engraved on titanium plates sealed in an airtight box stored in a safe buried in a desert protected by angry nomads riding giant sandworms because you're the frickin' Kwisatz Haderach, you still gain some benefit from Taproot)
And here's the important part: if P2PKH/P2WPKH is working perfectly fine with you and you decide to never use Taproot yourself, Taproot will not affect you detrimentally. First do no harm!

Taproot and Your Contracts

No one is an island, no one lives alone. Give and you shall receive. You know: by trading with other people, you can gain expertise in some obscure little necessity of the world (and greatly increase your productivity in that little field), and then trade the products of your expertise for necessities other people have created, all of you thereby gaining gains from trade.
So, contracts, which are basically enforceable agreements that facilitate trading with people who you do not personally know and therefore might not trust.
Let's start with a simple example. You want to buy some gewgaws from somebody. But you don't know them personally. The seller wants the money, you want their gewgaws, but because of the lack of trust (you don't know them!! what if they're scammers??) neither of you can benefit from gains from trade.
However, suppose both of you know of some entity that both of you trust. That entity can act as a trusted escrow. The entity provides you security: this enables the trade, allowing both of you to get gains from trade.
In Bitcoin-land, this can be implemented as a 2-of-3 multisignature. The three signatories in the multisgnature would be you, the gewgaw seller, and the escrow. You put the payment for the gewgaws into this 2-of-3 multisignature address.
Now, suppose it turns out neither of you are scammers (whaaaat!). You receive the gewgaws just fine and you're willing to pay up for them. Then you and the gewgaw seller just sign a transaction --- you and the gewgaw seller are 2, sufficient to trigger the 2-of-3 --- that spends from the 2-of-3 address to a singlesig the gewgaw seller wants (or whatever address the gewgaw seller wants).
But suppose some problem arises. The seller gave you gawgews instead of gewgaws. Or you decided to keep the gewgaws but not sign the transaction to release the funds to the seller. In either case, the escrow is notified, and if it can sign with you to refund the funds back to you (if the seller was a scammer) or it can sign with the seller to forward the funds to the seller (if you were a scammer).
Taproot helps with this: like mentioned above, it allows multisignature setups to produce only one signature, reducing blockchain space usage, and thus making contracts --- which require multiple people, by definition, you don't make contracts with yourself --- is made cheaper (which we hope enables more of these setups to happen for more gains from trade for everyone, also, moon and lambos).
(technology-wise, it's easier to make an n-of-n than a k-of-n, making a k-of-n would require a complex setup involving a long ritual with many communication rounds between the n participants, but an n-of-n can be done trivially with some moon math. You can, however, make what is effectively a 2-of-3 by using a three-branch SCRIPT: either 2-of-2 of you and seller, OR 2-of-2 of you and escrow, OR 2-of-2 of escrow and seller. Fortunately, Taproot adds a facility to embed a SCRIPT inside a public key, so you can have a 2-of-2 Taprooted address (between you and seller) with a SCRIPT branch that can instead be spent with 2-of-2 (you + escrow) OR 2-of-2 (seller + escrow), which implements the three-branched SCRIPT above. If neither of you are scammers (hopefully the common case) then you both sign using your keys and never have to contact the escrow, since you are just using the escrow public key without coordinating with them (because n-of-n is trivial but k-of-n requires setup with communication rounds), so in the "best case" where both of you are honest traders, you also get a privacy boost, in that the escrow never learns you have been trading on gewgaws, I mean ewww, gawgews are much better than gewgaws and therefore I now judge you for being a gewgaw enthusiast, you filthy gewgawer).

Taproot and Your Contracts, Part 2: Cryptographic Boogaloo

Now suppose you want to buy some data instead of things. For example, maybe you have some closed-source software in trial mode installed, and want to pay the developer for the full version. You want to pay for an activation code.
This can be done, today, by using an HTLC. The developer tells you the hash of the activation code. You pay to an HTLC, paying out to the developer if it reveals the preimage (the activation code), or refunding the money back to you after a pre-agreed timeout. If the developer claims the funds, it has to reveal the preimage, which is the activation code, and you can now activate your software. If the developer does not claim the funds by the timeout, you get refunded.
And you can do that, with HTLCs, today.
Of course, HTLCs do have problems:
Fortunately, with Schnorr (which is enabled by Taproot), we can now use the Scriptless Script constuction by Andrew Poelstra. This Scriptless Script allows a new construction, the PTLC or Pointlocked Timelocked Contract. Instead of hashes and preimages, just replace "hash" with "point" and "preimage" with "scalar".
Or as you might know them: "point" is really "public key" and "scalar" is really a "private key". What a PTLC does is that, given a particular public key, the pointlocked branch can be spent only if the spender reveals the private key of the given public key to you.
Another nice thing with PTLCs is that they are deniable. What appears onchain is just a single 2-of-2 signature between you and the developemanufacturer. It's like a magic trick. This signature has no special watermarks, it's a perfectly normal signature (the pledge). However, from this signature, plus some datta given to you by the developemanufacturer (known as the adaptor signature) you can derive the private key of a particular public key you both agree on (the turn). Anyone scraping the blockchain will just see signatures that look just like every other signature, and as long as nobody manages to hack you and get a copy of the adaptor signature or the private key, they cannot get the private key behind the public key (point) that the pointlocked branch needs (the prestige).
(Just to be clear, the public key you are getting the private key from, is distinct from the public key that the developemanufacturer will use for its funds. The activation key is different from the developer's onchain Bitcoin key, and it is the activation key whose private key you will be learning, not the developer's/manufacturer's onchain Bitcoin key).
So:
Taproot lets PTLCs exist onchain because they enable Schnorr, which is a requirement of PTLCs / Scriptless Script.
(technology-wise, take note that Scriptless Script works only for the "pointlocked" branch of the contract; you need normal Script, or a pre-signed nLockTimed transaction, for the "timelocked" branch. Since Taproot can embed a script, you can have the Taproot pubkey be a 2-of-2 to implement the Scriptless Script "pointlocked" branch, then have a hidden script that lets you recover the funds with an OP_CHECKLOCKTIMEVERIFY after the timeout if the seller does not claim the funds.)

Quantum Quibbles!

Now if you were really paying attention, you might have noticed this parenthetical:
(technical details: a Taproot output is 1 version byte + 32 byte public key, while a P2WPKH (bech32 singlesig) output is 1 version byte + 20 byte public key hash...)
So wait, Taproot uses raw 32-byte public keys, and not public key hashes? Isn't that more quantum-vulnerable??
Well, in theory yes. In practice, they probably are not.
It's not that hashes can be broken by quantum computes --- they're still not. Instead, you have to look at how you spend from a P2WPKH/P2PKH pay-to-public-key-hash.
When you spend from a P2PKH / P2WPKH, you have to reveal the public key. Then Bitcoin hashes it and checks if this matches with the public-key-hash, and only then actually validates the signature for that public key.
So an unconfirmed transaction, floating in the mempools of nodes globally, will show, in plain sight for everyone to see, your public key.
(public keys should be public, that's why they're called public keys, LOL)
And if quantum computers are fast enough to be of concern, then they are probably fast enough that, in the several minutes to several hours from broadcast to confirmation, they have already cracked the public key that is openly broadcast with your transaction. The owner of the quantum computer can now replace your unconfirmed transaction with one that pays the funds to itself. Even if you did not opt-in RBF, miners are still incentivized to support RBF on RBF-disabled transactions.
So the extra hash is not as significant a protection against quantum computers as you might think. Instead, the extra hash-and-compare needed is just extra validation effort.
Further, if you have ever, in the past, spent from the address, then there exists already a transaction indelibly stored on the blockchain, openly displaying the public key from which quantum computers can derive the private key. So those are still vulnerable to quantum computers.
For the most part, the cryptographers behind Taproot (and Bitcoin Core) are of the opinion that quantum computers capable of cracking Bitcoin pubkeys are unlikely to appear within a decade or two.
So:
For now, the homomorphic and linear properties of elliptic curve cryptography provide a lot of benefits --- particularly the linearity property is what enables Scriptless Script and simple multisignature (i.e. multisignatures that are just 1 signature onchain). So it might be a good idea to take advantage of them now while we are still fairly safe against quantum computers. It seems likely that quantum-safe signature schemes are nonlinear (thus losing these advantages).

Summary

I Wanna Be The Taprooter!

So, do you want to help activate Taproot? Here's what you, mister sovereign Bitcoin HODLer, can do!

But I Hate Taproot!!

That's fine!

Discussions About Taproot Activation

submitted by almkglor to Bitcoin [link] [comments]

Technical: Confidential Transactions and Their Implementation Tradeoffs

As requested by estradata here: https://old.reddit.com/Bitcoin/comments/iylou9/what_are_some_of_the_latest_innovations_in_the/g6heez1/
It is a general issue that crops up at the extremes of cryptography, with quantum breaks being just one of the extremes of (classical) cryptography.

Computational vs Information-Theoretic

The dichotomy is between computationally infeasible vs informationally-theoretic infeasible. Basically:
Quantum breaks represent a possible reduction in computational infeasibility of certain things, but not information-theoretic infeasibility.
For example, suppose you want to know what 256-bit preimages map to 256-bit hashes. In theory, you just need to build a table with 2256 entries and start from 0x0000000000000000000000000000000000000000000000000000000000000000 and so on. This is computationally infeasible, but not information-theoretic infeasible.
However, suppose you want to know what preimages, of any size, map to 256-bit hashes. Since the preimages can be of any size, after finishing with 256-bit preimages, you have to proceed to 257-bit preimages. And so on. And there is no size limit, so you will literally never finish. Even if you lived forever, you would not complete it. This is information-theoretic infeasible.

Commitments

How does this relate to confidential transactions? Basically, every confidential transaction simply hides the value behind a homomorphic commitment. What is a homomorphic commitment? Okay, let's start with commitments. A commitment is something which lets you hide something, and later reveal what you hid. Until you reveal it, even if somebody has access to the commitment, they cannot reverse it to find out what you hid. This is called the "hiding property" of commitments. However, when you do reveal it (or "open the commitment"), then you cannot replace what you hid with some other thing. This is called the "binding property" of commitments.
For example, a hash of a preimage is a commitment. Suppose I want to commit to something. For example, I want to show that I can predict the future using the energy of a spare galaxy I have in my pocket. I can hide that something by hashing a description of the future. Then I can give the hash to you. You still cannot learn the future, because it's just a hash, and you can't reverse the hash ("hiding"). But suppose the future event occurs. I can reveal that I did, in fact, know the future. So I give you the description, and you hash it and compare it to the hash I gave earlier. Because of preimage resistance, I cannot retroactively change what I hid in the hash, so what I gave must have been known to me at the time that I gave you the commitment i..e. hash ("binding").

Homomorphic Commitments

A homomorphic commitment simply means that if I can do certain operations on preimages of the commitment scheme, there are certain operations on the commitments that would create similar ("homo") changes ("morphic") to the commitments. For example, suppose I have a magical function h() which is a homomorphic commitment scheme. It can hide very large (near 256-bit) numbers. Then if h() is homomorphic, there may be certain operations on numbers behind the h() that have homomorphisms after the h(). For example, I might have an operation <+> that is homomorphic in h() on +, or in other words, if I have two large numbers a and b, then h(a + b) = h(a) <+> h(b). + and <+> are different operations, but they are homomorphic to each other.
For example, elliptic curve scalars and points have homomorphic operations. Scalars (private keys) are "just" very large near-256-bit numbers, while points are a scalar times a standard generator point G. Elliptic curve operations exist where there is a <+> between points that is homomorphic on standard + on scalars, and a <*> between a scalar and a point that is homomorphic on standard * multiplication on scalars.
For example, suppose I have two large scalars a and b. I can use elliptic curve points as a commitment scheme: I can take a <*> G to generate a point A. It is hiding since nobody can learn what a is unless I reveal it (a and A can be used in standard ECDSA private-public key cryptography, with the scalar a as the private key and the point A as the public key, and the a cannot be derived even if somebody else knows A). Thus, it is hiding. At the same time, for a particular point A and standard generator point G, there is only one possible scalar a which when "multiplied" with G yields A. So scalars and elliptic curve points are a commitment scheme, with both hiding and binding properties.
Now, as mentioned there is a <+> operation on points that is homomorphic to the + operation on corresponding scalars. For example, suppose there are two scalars a and b. I can compute (a + b) <*> G to generate a particular point. But even if I don't know scalars a and b, but I do know points A = a <*> G and B = b <*> G, then I can use A <+> B to derive (a + b) <*> G (or equivalently, (a <*> G) <+> (b <*> G) == (a + b) <*> G). This makes points a homomorphic commitment scheme on scalars.

Confidential Transactions: A Sketch

This is useful since we can easily use the near-256-bit scalars in SECP256K1 elliptic curves to easily represent values in a monetary system, and hide those values by using a homomorphic commitment scheme. We can use the hiding property to prevent people from learning the values of the money we are sending and receiving.
Now, in a proper cryptocurrency, a normal, non-coinbase transaction does not create or destroy coins: the values of the input coins are equal to the value of the output coins. We can use a homomorphic commitment scheme. Suppose I have a transaction that consumes an input value a and creates two output values b and c. That is, a = b + c, i.e. the sum of all inputs a equals the sum of all outputs b and c. But remember, with a homomorphic commitment scheme like elliptic curve points, there exists a <+> operation on points that is homomorphic to the ordinary school-arithmetic + addition on large numbers. So, confidential transactions can use points a <*> G as input, and points b <*> G and c <*> G as output, and we can easily prove that a <*> G = (b <*> G) <+> (c <*> G) if a = b + c, without revealing a, b, or c to anyone.

Pedersen Commitments

Actually, we cannot just use a <*> G as a commitment scheme in practice. Remember, Bitcoin has a cap on the number of satoshis ever to be created, and it's less than 253 satoshis, which is fairly trivial. I can easily compute all values of a <*> G for all values of a from 0 to 253 and know which a <*> G corresponds to which actual amount a. So in confidential transactions, we cannot naively use a <*> G commitments, we need Pedersen commitments.
If you know what a "salt" is, then Pedersen commitments are fairly obvious. A "salt" is something you add to e.g. a password so that the hash of the password is much harder to attack. Humans are idiots and when asked to generate passwords, will output a password that takes less than 230 possibilities, which is fairly easy to grind. So what you do is that you "salt" a password by prepending a random string to it. You then hash the random string + password, and store the random string --- the salt --- together with the hash in your database. Then when somebody logs in, you take the password, prepend the salt, hash, and check if the hash matches with the in-database hash, and you let them log in. Now, with a hash, even if somebody copies your password database, the can't get the password. They're hashed. But with a salt, even techniques like rainbow tables make a hacker's life even harder. They can't hash a possible password and check every hash in your db for something that matches. Instead, if they get a possible password, they have to prepend each salt, hash, then compare. That greatly increases the computational needs of a hacker, which is why salts are good.
What a Pedersen commitment is, is a point a <*> H, where a is the actual value you commit to, plus <+> another point r <*> G. H here is a second standard generator point, different from G. The r is the salt in the Pedersen commitment. It makes it so that even if you show (a <*> H) <+> (r <*> G) to somebody, they can't grind all possible values of a and try to match it with your point --- they also have to grind r (just as with the password-salt example above). And r is much larger, it can be a true near-256-bit number that is the range of scalars in SECP256K1, whereas a is constrained to "reasonable" numbers of satoshi, which cannot exceed 21 million Bitcoins.
Now, in order to validate a transaction with input a and outputs b and c, you only have to prove a = b + c. Suppose we are hiding those amounts using Pedersen commitments. You have an input of amount a, and you know a and r. The blockchain has an amount (a <*> H) <+> (r <*> G). In order to create the two outputs b and c, you just have to create two new r scalars such that r = r[0] + r[1]. This is trivial, you just select a new random r[0] and then compute r[1] = r - r[0], it's just basic algebra.
Then you create a transaction consuming the input (a <*> H) <+> (r <*> G) and outputs (b <*> H) <+> (r[0] <*> G) and (c <*> H) <+> (r[1] <*> G). You know that a = b + c, and r = r[0] + r[1], while fullnodes around the world, who don't know any of the amounts or scalars involved, can just take the points (a <*> H) <+> (r <*> G) and see if it equals (b <*> H) <+> (r[0] <*> G) <+> (c <*> H) <+> (r[1] <*> G). That is all that fullnodes have to validate, they just need to perform <+> operations on points and comparison on points, and from there they validate transactions, all without knowing the actual values involved.

Computational Binding, Information-Theoretic Hiding

Like all commitments, Pedersen Commitments are binding and hiding.
However, there are really two kinds of commitments:
What does this mean? It's just a measure of how "impossible" binding vs hiding is. Pedersen commitments are computationally binding, meaning that in theory, a user of this commitment with arbitrary time and space and energy can, in theory, replace the amount with something else. However, it is information-theoretic hiding, meaning an attacker with arbitrary time and space and energy cannot figure out exactly what got hidden behind the commitment.
But why?
Now, we have been using a and a <*> G as private keys and public keys in ECDSA and Schnorr. There is an operation <*> on a scalar and a point that generates another point, but we cannot "revrese" this operation. For example, even if I know A, and know that A = a <*> G, but do not know a, I cannot derive a --- there is no operation between A G that lets me know a.
Actually there is: I "just" need to have so much time, space, and energy that I just start counting a from 0 to 2256 and find which a results in A = a <*> G. This is a computational limit: I don't have a spare universe in my back pocket I can use to do all those computations.
Now, replace a with h and A with H. Remember that Pedersen commitments use a "second" standard generator point. The generator points G and H are "not really special" --- they are just random points on the curve that we selected and standardized. There is no operation H G such that I can learn h where H = h <*> G, though if I happen to have a spare universe in my back pocket I can "just" brute force it.
Suppose I do have a spare universe in my back pocket, and learn h = H G such that H = h <*> G. What can I do in Pedersen commitments?
Well, I have an amount a that is committed to by (a <*> H) <+> (r <*> G). But I happen to know h! Suppose I want to double my money a without involving Elon Musk. Then:
That is what we mean by computationally binding: if I can compute h such that H = h <*> G, then I can find another number which opens the same commitment. And of course I'd make sure that number is much larger than what I originally had in that address!
Now, the reason why it is "only" computationally binding is that it is information-theoretically hiding. Suppose somebody knows h, but has no money in the cryptocurrency. All they see are points. They can try to find what the original amounts are, but because any amount can be mapped to "the same" point with knowledge of h (e.g. in the above, a and 2 * a got mapped to the same point by "just" replacing the salt r with r - a * h; this can be done for 3 * a, 4 * a etc.), they cannot learn historical amounts --- the a in historical amounts could be anything.
The drawback, though, is that --- as seen above --- arbitrary inflation is now introduced once somebody knows h. They can multiply their money by any arbitrary factor with knowledge of h.
It is impossible to have both perfect hiding (i.e. historical amounts remain hidden even after a computational break) and perfect binding (i.e. you can't later open the commitment to a different, much larger, amount).
Pedersen commitments just happen to have perfect hiding, but only computationally-infeasible binding. This means they allow hiding historical values, but in case of anything that allows better computational power --- including but not limited to quantum breaks --- they allow arbitrary inflation.

Changing The Tradeoffs with ElGamal Commitments

An ElGamal commitment is just a Pedersen commitment, but with the point r <*> G also stored in a separate section of the transaction.
This commits the r, and fixes it to a specific value. This prevents me from opening my (a <*> H) <+> (r <*> G) as ((2 * a) <*> H) <+> ((r - a * h) <*> G), because the (r - a * h) would not match the r <*> G sitting in a separate section of the transaction. This forces me to be bound to that specific value, and no amount of computation power will let me escape --- it is information-theoretically binding i.e. perfectly binding.
But that is now computationally hiding. An evil surveillor with arbitrary time and space can focus on the r <*> G sitting in a separate section of the transaction, and grind r from 0 to 2256 to determine what r matches that point. Then from there, they can negate r to get (-r) <*> G and add it to the (a <*> H) <+> (r <*> G) to get a <*> H, and then grind that to determine the value a. With massive increases in computational ability --- including but not limited to quantum breaks --- an evil surveillor can see all the historical amounts of confidential transactions.

Conclusion

This is the source of the tradeoff: either you design confidential transactions so in case of a quantum break, historical transactions continue to hide their amounts, but inflation of the money is now unavoidable, OR you make the money supply sacrosanct, but you potentially sacrifice amount hiding in case of some break, including but not limited to quantum breaks.
submitted by almkglor to Bitcoin [link] [comments]

Flatten the Curve. #49. Let's Dig into Jade Helm. AI. The Surveillance State. Internet of Things. FISA. Pentagon Preparing for Mass Civil Breakdown. What is Mob Excess Deterrent Using Silent Audio? Stay Aware and Get Ahead of the Curve.

Flatten the Curve. Part 48. Source Here
It's getting crazier day by day now, so are you following the Boy Scout motto?
On this topic, Baden-Powell says: Remember your motto, "Be Prepared." Be prepared for accidents by learning beforehand what you ought to do in the different kinds that are likely to occur. Be prepared to do that thing the moment the accident does occur. In Scouting for Boys, Baden-Powell wrote that to Be Prepared means “you are always in a state of readiness in mind and body to do your duty.”
Why should you be prepared? Because TPTB have been preparing, that’s why.
June 12, 2014: The Guardian • Pentagon preparing for mass civil breakdown. Social science is being militarised to develop 'operational tools' to target peaceful activists and protest movements Source Here
Pentagon preparing for mass civil breakdown. It seemed ludicrous back in 2014, didn't it? Inconceivable. Sure some preppers believed it, but they're always getting ready and nothing happened. Doomsday was always right around the corner, and then the next corner, and on and on. Televangelists have probably accused more politicians of being the antichrist than the number of politicians went to Epstein's Island.
But why would they be preparing for mass civil breakdown? Could it be the same reason as why the miltary is preparing for war, droughts and famines brought about by environmental collapse?
February 20, 2020: History Network • Here’s Why These Six Ancient Civilizations Mysteriously Collapsed. From the Maya to Greenland’s Vikings, check out six civilizations that seemingly disappeared without a trace. Source Here
All of these civilizations vanished because of some combination of exhausting their natural resources, drought, plauge, and the little ice age. Sound familiar? Don't tell me that the Rockefeller Foundation and BlackRock became environmentally aware out of a sense of obligation to the planet. They're setting the groundwork for what's coming down the pipe. This isn't about money anymore, this is about control and survival. Throw out the rulebook because the rules no longer apply.
Do you think the surveillance system is for your protection, or the protection of the state? Don't you think that an era of upcoming calamities will severely damage the communication networks, and thus the surveillance system? It might be prudent to consider that Starlink is being established to make the system redundant, so that they never lose track of the precious worker bees before they can be connected to the AI hive mind, right Elon? Neuralink, don't leave home without it.
But let's not forget about the wonderful world of the Internet of Things.
March 15, 2012 • More and more personal and household devices are connecting to the internet, from your television to your car navigation systems to your light switches. CIA Director David Petraeus cannot wait to spy on you through them. Earlier this month, Petraeus mused about the emergence of an "Internet of Things" -- that is, wired devices -- at a summit for In-Q-Tel, the CIA's venture capital firm. "'Transformational' is an overused word, but I do believe it properly applies to these technologies," Petraeus enthused, "particularly to their effect on clandestine tradecraft." All those new online devices are a treasure trove of data if you're a "person of interest" to the spy community. Once upon a time, spies had to place a bug in your chandelier to hear your conversation. With the rise of the "smart home," you'd be sending tagged, geolocated data that a spy agency can intercept in real time when you use the lighting app on your phone to adjust your living room's ambiance. "Items of interest will be located, identified, monitored, and remotely controlled through technologies such as radio-frequency identification, sensor networks, tiny embedded servers, and energy harvesters -- all connected to the next-generation internet using abundant, low-cost, and high-power computing," Petraeus said, "the latter now going to cloud computing, in many areas greater and greater supercomputing, and, ultimately, heading to quantum computing." Petraeus allowed that these household spy devices "change our notions of secrecy" and prompt a rethink of "our notions of identity and secrecy." All of which is true -- if convenient for a CIA director. The CIA has a lot of legal restrictions against spying on American citizens. But collecting ambient geolocation data from devices is a grayer area, especially after the 2008 carve-outs to the Foreign Intelligence Surveillance Act. Hardware manufacturers, it turns out, store a trove of geolocation data; and some legislators have grown alarmed at how easy it is for the government to track you through your phone or PlayStation. That's not the only data exploit intriguing Petraeus. He's interested in creating new online identities for his undercover spies -- and sweeping away the "digital footprints" of agents who suddenly need to vanish. "Proud parents document the arrival and growth of their future CIA officer in all forms of social media that the world can access for decades to come," Petraeus observed. "Moreover, we have to figure out how to create the digital footprint for new identities for some officers." Source Here
December 19, 2019: New York Times • THE DATA REVIEWED BY TIMES OPINION didn’t come from a telecom or giant tech company, nor did it come from a governmental surveillance operation. It originated from a location data company, one of dozens quietly collecting precise movements using software slipped onto mobile phone apps. You’ve probably never heard of most of the companies — and yet to anyone who has access to this data, your life is an open book. They can see the places you go every moment of the day, whom you meet with or spend the night with, where you pray, whether you visit a methadone clinic, a psychiatrist’s office or a massage parlor. The Times and other news organizations have reported on smartphone tracking in the past. But never with a data set so large. Even still, this file represents just a small slice of what’s collected and sold every day by the location tracking industry — surveillance so omnipresent in our digital lives that it now seems impossible for anyone to avoid. It doesn’t take much imagination to conjure the powers such always-on surveillance can provide an authoritarian regime like China’s. Within America’s own representative democracy, citizens would surely rise up in outrage if the government attempted to mandate that every person above the age of 12 carry a tracking device that revealed their location 24 hours a day. Yet, in the decade since Apple’s App Store was created, Americans have, app by app, consented to just such a system run by private companies. Now, as the decade ends, tens of millions of Americans, including many children, find themselves carrying spies in their pockets during the day and leaving them beside their beds at night — even though the corporations that control their data are far less accountable than the government would be. Source Here
The IoT should be renamed to IoTT (Internet of Tracking Things), shouldn't it. But we can't have people figure out what's really happening, can we? It's a good thing that quantum computing isn't too close, isn’t it?
April 5, 2018: Global News • (Project Maven) Over 3,000 Google employees have a signed a petition in protest against the company’s involvement with a U.S. Department of Defense artificial intelligence (AI) project that studies imagery and could eventually be used to improve drone strikes in the battlefield. Source Here
December 12, 2019 • Palantir took over Project Maven defense contract after Google backed out. Source Here
December 29, 2020: Input • Palantir exec says its work is on par with the Manhattan Project. Comparing AI to most lethal weapon in human history isn’t comforting. SourceHere
August 14, 2020: Venture: • Google researchers use quantum computing to help improve image classification. Source Here
Hmmm. Maybe Apple will be for the little guy? They have always valued privacy rights, right?
October 2, 2013: Vice News • The hacktivist group Anonymous released a video statement with an accompanying Pastebin document claiming that there are definitive links between AuthenTec, the company that developed the iPhone 5S’s fingerprint scanner, and the US government. Source Here
An apple a day helps the NSA. Or Google. Or Microsoft. Or Amazon. Take your pick from the basket, because dem Apple's are all the same. But at least we have fundamental rights, right?
Foreign agent declaration not required • No mention of foreign agent status is made in the Protect America Act of 2007. Under prior FISA rules, persons targeted for surveillance must have been declared as foreign agents before a FISA warrant would be accorded by the FISC court.
'Quasi-anti-terrorism law' for all-forms of intelligence collection • Vastly marketed by U.S. federal and military agencies as a law to prevent terror attacks, the Protect America Act was actually a law focused on the 'acquisition' of desired intelligence information, of unspecified nature. The sole requirement is geolocation outside the United States at time of Directive invocation; pursuant to Authorization or Order invocation, surveillance Directives can be undertaken towards persons targeted for intelligence information gathering. Implementation of Directives can take place inside the United States or outside the United States. No criminal or terrorism investigation of the person need be in play at time of the Directive. All that need be required is that the target be related to an official desire for intelligence information gathering for actions on part of persons involved in surveillance to be granted full immunity from U.S. criminal or civil procedures, under Section 105B(l) of the Act.
Removal of FISA Strictures from warrant authorization; warrants not required • But the most striking aspect of the Protect America Act was the notation that any information gathering did not comprise electronic surveillance. This wording had the effect of removing FISA-related strictures from Protect America Act 2007-related Directives, serving to remove a number of protections for persons targeted, and requirements for persons working for U.S. intelligence agencies.
The acquisition does not constitute electronic surveillance • The removal of the term electronic surveillance from any Protect America Act Directive implied that the FISC court approval was no longer required, as FISA warrants were no longer required. In the place of a warrant was a certification, made by U.S. intelligence officers, which was copied to the Court. In effect, the FISC became less of a court than a registry of pre-approved certifications.Certifications (in place of FISA warrants) were able to be levied ex post facto, in writing to the Court no more than 72 hours after it was made. The Attorney General was to transmit as soon as possible to the Court a sealed copy of the certification that would remain sealed unless the certification was needed to determine the legality of the acquisition.Source Here
Oh. FISA is basically a rubber stamp. And even if it the stage play wasn't pretending to follow the script, would it matter? Who could actually stop it at this point? The cat's out of the bag and Pandoras Box is open.
Controversial debates arose as the Protect America Act was published. Constitutional lawyers and civil liberties experts expressed concerns that this Act authorized massive, wide-ranging information gathering with no oversight. Whereas it placed much focus on communications, the Act allowed for information gathering of all shapes and forms. The ACLU called it the "Police America Act" – "authorized a massive surveillance dragnet", calling the blank-check oversight provisions "meaningless," and calling them a "phony court review of secret procedures."
So the surveillance state doesn't have checks and balances anymore. The state is preparing for Massive Civil Breakdown. They keep warning us about environmental collapse. Got it? Good. Let's keep on keeping on.
The District of Columbia Organic Act of 1871 created a single new district corporation governing the entire federal territory, called the District of Columbia, thus dissolving the three major political subdivisions of the District (Port of Georgetown, the City of Washington, and Washington County) and their governments. Source Here)
The first big leap in corporate personhood from holding mere property and contract rights to possessing more expansive rights was a claim that the Equal Protection Clause applied to corporations. One of the strangest twists in American constitutional law was the moment that corporations gained personhood under the Equal Protection Clause of the Fourteenth Amendment. It occurred in a case called Santa Clara County, and what was odd was that the Supreme Court did not really even decide the matter in the actual opinion. It only appeared in a footnote to the case. What we are likely to have at the conclusion of the Supreme Court term is corporations that are empowered to spend in American elections because of Bellotti and Citizens United; corporations that can make religious objections thanks to Hobby Lobby; and if Jesner turns out as badly as I predict, corporations will be able to aid and abet human rights violations abroad with impunity. Source Here
"Having a corporation would allow people to put property into a collective ownership that could be held with perpetual existence," she says. "So it wouldn't be tied to any one person's lifespan, or subject necessarily to laws regarding inheriting property." Later on, in the United States and elsewhere, the advantages of incorporation were essential to efficient and secure economic development. Unlike partnerships, the corporation continued to exist even if a partner died; there was no unanimity required to do something; shareholders could not be sued individually, only the corporation as a whole, so investors only risked as much as they put into buying shares. Source Here
The way that the Arab Bank may get away with this alleged morally troubling behavior, even though it has a New York branch, is by reasserting the basic argument that was made in Nestle USA and Kiobel II: that the federal Alien Tort Statute was not intended to apply to corporations full stop. Given other cases in this area like Mohamad v. PLO, which held the word “individual” in the Torture Victim Protection Act means a natural person and does not impose any liability against organizations, the Arab Bank’s procorporate argument may well prevail. There are multiple federal Circuit Courts which have shot down the argument that corporations are immune from suit under the Alien Tort Statute. The lone outlier is the Second Circuit, which decided in 2010 that corporations are excused from suit in Kiobel I. This is the case that was appealed to the Supreme Court and became Kiobel II. Jesner v. Arab Bank was litigated in the Second Circuit. One question in Jesner was what exactly did Kiobel II do to Kiobel I. So far in the litigation, Jesner concluded that Kiobel I and its conclusion that corporations can’t be sued in federal court using the Alien Tort Statute remained the controlling law of the Second Circuit.
There's a reason people call lawyers snakes, it's because most of them speak with forked tounges. So the corporation isn't being held liable, but the shareholders can't be held liable either. That's too insane to even be called a Catch 22. We are literally being set up to have no recourse because there isn’t anybody who can be held responsible. Why is that important when I've been talking about the surveillance state?
July 14, 2020: The Intercept • Microsoft’s police surveillance services are often opaque because the company sells little in the way of its own policing products. It instead offers an array of “general purpose” Azure cloud services, such as machine learning and predictive analytics tools like Power BI (business intelligence) and Cognitive Services, which can be used by law enforcement agencies and surveillance vendors to build their own software or solutions. A rich array of Microsoft’s cloud-based offerings is on full display with a concept called “The Connected Officer.” Microsoft situates this concept as part of the Internet of Things, or IoT, in which gadgets are connected to online servers and thus made more useful. “The Connected Officer,” Microsoft has written, will “bring IoT to policing.” With the Internet of Things, physical objects are assigned unique identifiers and transfer data over networks in an automated fashion. If a police officer draws a gun from its holster, for example, a notification can be sent over the network to alert other officers there may be danger. Real Time Crime Centers could then locate the officer on a map and monitor the situation from a command and control center. Source Here
Uhm, I guess it's really is all connected, isn’t it?
June 18, 2020: The Guardian • How Target, Google, Bank of America and Microsoft quietly fund police through private donations. More than 25 large corporations in the past three years have contributed funding to private police foundations, new report says. Source Here
Long live the Military Industrial Techno Surveillance State. If you have nothing to hide, than you have nothing to worry about. Really? Are we still believing that line? Cause it's a load of crap. If we have nothing to worry about, then why are they worried enough to be implementing surveillance systems with corresponding units on the ground? Got your attention there, didn't I?
August 19, 2019: Big Think • Though the term "Orwellian" easily applies to such a technology, Michel's illuminating reporting touches something deeper. Numerous American cities have already been surveilled using these god-like cameras, including Gorgon Stare, a camera-enabled drone that can track individuals over a 50-square kilometer radius from 20,000 feet. Here's the real rub: the feature that allows users to pinch and zoom on Instagram is similar to what WAMI allows. Anything within those 50-square kilometers is now under the microscope. If this sounds like some futuristic tech, think again: Derivations of this camera system have been tested in numerous American cities. Say there is a big public protest. With this camera you can follow thousands of protesters back to their homes. Now you have a list of the home addresses of all the people involved in a political movement. If on their way home you witness them committing some crime—breaking a traffic regulation or frequenting a location that is known to be involved in the drug trade—you can use that surveillance data against them to essentially shut them up. That's why we have laws that prevent the use of surveillance technologies because it is human instinct to abuse them. That's why we need controls. Source Here
Want to know more about the Gorgon Stare? Flatten the Curve. Part 12. Source Here
Now, I'm not sure if you remember or know any Greek Mythology, but the Gorgons were three sisters, and one sister had Snakes on her head (she wasn't a lawyer) and she turned people to stone when she looked at them.
MEDUSA (Mob Excess Deterrent Using Silent Audio) is a directed-energy non-lethal weapon designed by WaveBand Corporation in 2003-2004 for temporary personnel incapacitation. The weapon is based on the microwave auditory effect resulting in a strong sound sensation in the human head when it is subject to certain kinds of pulsed/modulated microwave radiation. The developers claimed that through the combination of pulse parameters and pulse power, it is possible to raise the auditory sensation to a “discomfort” level, deterring personnel from entering a protected perimeter or, if necessary, temporarily incapacitating particular individuals. In 2005, Sierra Nevada Corporation acquired WaveBand Corporation.
Ok. Get it? The Gorgon eye in the sky stares at you while the Medusa makes you immobile. Not good, but at least it'll just freeze you in your tracks.
July 6, 2008: Gizmodo • The Sierra Nevada Corporation claimed this week that it is ready to begin production on the MEDUSA, a damned scary ray gun that uses the "microwave audio effect" to implant sounds and perhaps even specific messages inside people's heads. Short for Mob Excess Deterrent Using Silent Audio, MEDUSA creates the audio effect with short microwave pulses. The pulses create a shockwave inside the skull that's detected by the ears, and basically makes you think you're going balls-to-the-wall batshit insane. Source Here
Uhm. And drive you insane.
July 26, 2008: Gizmodo • The MEDUSA crowd control ray gun we reported on earlier this month sounded like some pretty amazing-and downright scary-technology. Using the microwave auditory effect, the beam, in theory, would have put sounds and voice-like noises in your head, thereby driving you away from the area. Crowd control via voices in your head. Sounds cool. However, it turns out that the beam would actually kill you before any of that happy stuff started taking place, most likely by frying or cooking your brain inside your skull. Can you imagine if this thing made it out into the field? Awkward! Source Here
Annnnnnnndddddd it'll kill you.
Guys, they're prepared. They've been prepared. They're ready. Remember the Doomsday Bunkers? The military moving into Cheyenne Mountain? Deep Underground Military Bunkers? The rapid rolling out of 5G? BITCOIN and UBI so neatly inserted into our minds over the last five years? They've directly told us to have three months of supplies in our homes. 2020 isn't going to be an anomaly? It's the start of the collapse of our natural resources. Take a look on Reddit and all the posts about crazy weather. Cyanobacteria blooms killing dogs and people. Toxic Super Pollution caused by atmospheric inversions killing people. This isn’t normal, this is New Normal. And they know it. They've known it for a while. Let me show you one last thing before I wrap it up.
From the earliest Chinese dynasties to the present, the jade deposits most used were not only those of Khotan in the Western Chinese province of Xinjiang but other parts of China as well, such as Lantian, Shaanxi.
Remember, words matter. Look at Gorgon Stare and Medusa. They don't randomly grab names out of a hat, or pick them because they think it sounds dystopian. They pick words for a reason.
July 7, 2017: The Warzone • There only appears to be one official news story on this exercise at all and it's available on the website of Air Mobility Command’s Eighteenth Air Force, situated at Joint Base Charleston. At the time of writing, a google shows that there were more than a half dozen more copies on other Air Force pages, as well as number of photographs. For some reason, someone appears to have taken these offline or otherwise broken all the links. Using Google to search the Defense Video Imagery Distribution System, which is the main U.S. military's public affairs hub, brings up more broken links. Oh, and unless there's been some sort of mistake, JADE HELM actually stands for the amazingly obtuse Joint Assistance for Deployment Execution Homeland Eradication of Local Militants. A separate web search for this phrase does not turn up any other results. Source Here
Now, using an acronym that indicates training to Eradicate Local Militants seems pretty dumb. It may be used in that manner if environmental collapse triggers riots, but i don't think they would warn everyone ahead of time, do you? So I dug a little bit more.
Joint Assistant for Development and Execution (JADE) is a U.S. military system used for planning the deployment of military forces in crisis situations. The U.S. military developed this automated planning software system in order to expedite the creation of the detailed planning needed to deploy military forces for a military operation. JADE uses Artificial Intelligence (AI) technology combining user input, a knowledge base of stored plans, and suggestions by the system to provide the ability to develop large-scale and complex plans in minimal time. JADE is a knowledge-based system that uses highly structured information that takes advantage of data hierarchies. An official 2016 document approved for public release titled Human Systems Roadmap Review describes plans to create autonomous weapon systems that analyze social media and make decisions, including the use of lethal force, with minimal human involvement. This type of system is referred to as a Lethal Autonomous Weapon System (LAWS). The name "JADE" comes from the jade green color seen on the island of Oahu in Hawaii where the U.S. Pacific Command (PACOM) is headquartered.
PACOM? Why isn't that command group responsible for the South China Sea?
Formerly known as United States Pacific Command (USPACOM) since its inception, the command was renamed to U.S. Indo-Pacific Command on 30 May 2018, in recognition of the greater emphasis on South Asia, especially India.
Now doesn't it look like Jade Helm is preparing for an invasion? And possibly insurrection later. Or at the same time? Or riots over WW3? Or food riots? And start thinking about why the laws are starting to exclude corporations? Then think about the mercenaries that are being contracted out by the government.
October 17, 2018: The Carolinan • In 2016, 75 percent of American forces were private contractors. In 2017, Erik Prince, former head of Blackwater, and Stephen Feinberg, head of Dyncorp, discussed plans for contractors completely taking over U.S. operations in Afghanistan. Although ultimately unsuccessful, it remains to be seen if the current administration will change its mind. Contractors are involved in almost every military task, such as intelligence analysis, logistics and training allied soldiers. Contractors are even involved in U.S. special ops missions. This is because contractors are essentially untraceable and unaccountable. Most are born in other countries; only 33 percent are registered U.S. citizens. Private military firms don’t have to report their actions to Congress, unlike the military or intelligence agencies. They also aren’t subject to the Freedom of Information Act, so private citizens and journalists aren’t allowed to access their internal documents. There are also no international laws to regulate private military firms. It’s been proven that many contractors are involved in illegal activities. The larger multinational companies sometimes hire local subcontractors. These contractors sometimes aren’t background-checked. A 2010 investigation by the Senate found that many subcontractors were linked to murders, kidnappings, bribery and anti-coalition activities. Some subcontractors even formed their own unlicensed mercenary groups after coalition forces leave. A 2010 House investigation showed evidence that the Department of Defense had hired local warlords for security services. In 2007, Blackwater contractors massacred 17 civilians. This eventually led Blackwater to being restructured and renamed as Academi. Source Here
Military Exercises. Private Defense Firms. No oversight. And it's all coming soon. Read more at Flatten the Curve. Part 20. Upcoming war and catastrophes. Source Here
Nah. I'm just fear mongering and Doomscrolling again.
Heads up and eyes open. Talk soon.
submitted by biggreekgeek to conspiracy [link] [comments]

[ Bitcoin ] Technical: Taproot: Why Activate?

Topic originally posted in Bitcoin by almkglor [link]
This is a follow-up on https://old.reddit.com/Bitcoin/comments/hqzp14/technical_the_path_to_taproot_activation/
Taproot! Everybody wants it!! But... you might ask yourself: sure, everybody else wants it, but why would I, sovereign Bitcoin HODLer, want it? Surely I can be better than everybody else because I swapped XXX fiat for Bitcoin unlike all those nocoiners?
And it is important for you to know the reasons why you, o sovereign Bitcoiner, would want Taproot activated. After all, your nodes (or the nodes your wallets use, which if you are SPV, you hopefully can pester to your wallet vendoimplementor about) need to be upgraded in order for Taproot activation to actually succeed instead of becoming a hot sticky mess.
First, let's consider some principles of Bitcoin.
I'm sure most of us here would agree that the above are very important principles of Bitcoin and that these are principles we would not be willing to remove. If anything, we would want those principles strengthened (especially the last one, financial privacy, which current Bitcoin is only sporadically strong with: you can get privacy, it just requires effort to do so).
So, how does Taproot affect those principles?

Taproot and Your /Coins

Most HODLers probably HODL their coins in singlesig addresses. Sadly, switching to Taproot would do very little for you (it gives a mild discount at spend time, at the cost of a mild increase in fee at receive time (paid by whoever sends to you, so if it's a self-send from a P2PKH or bech32 address, you pay for this); mostly a wash).
(technical details: a Taproot output is 1 version byte + 32 byte public key, while a P2WPKH (bech32 singlesig) output is 1 version byte + 20 byte public key hash, so the Taproot output spends 12 bytes more; spending from a P2WPKH requires revealing a 32-byte public key later, which is not needed with Taproot, and Taproot signatures are about 9 bytes smaller than P2WPKH signatures, but the 32 bytes plus 9 bytes is divided by 4 because of the witness discount, so it saves about 11 bytes; mostly a wash, it increases blockweight by about 1 virtual byte, 4 weight for each Taproot-output-input, compared to P2WPKH-output-input).
However, as your HODLings grow in value, you might start wondering if multisignature k-of-n setups might be better for the security of your savings. And it is in multisignature that Taproot starts to give benefits!
Taproot switches to using Schnorr signing scheme. Schnorr makes key aggregation -- constructing a single public key from multiple public keys -- almost as trivial as adding numbers together. "Almost" because it involves some fairly advanced math instead of simple boring number adding, but hey when was the last time you added up your grocery list prices by hand huh?
With current P2SH and P2WSH multisignature schemes, if you have a 2-of-3 setup, then to spend, you need to provide two different signatures from two different public keys. With Taproot, you can create, using special moon math, a single public key that represents your 2-of-3 setup. Then you just put two of your devices together, have them communicate to each other (this can be done airgapped, in theory, by sending QR codes: the software to do this is not even being built yet, but that's because Taproot hasn't activated yet!), and they will make a single signature to authorize any spend from your 2-of-3 address. That's 73 witness bytes -- 18.25 virtual bytes -- of signatures you save!
And if you decide that your current setup with 1-of-1 P2PKH / P2WPKH addresses is just fine as-is: well, that's the whole point of a softfork: backwards-compatibility; you can receive from Taproot users just fine, and once your wallet is updated for Taproot-sending support, you can send to Taproot users just fine as well!
(P2WPKH and P2WSH -- SegWit v0 -- addresses start with bc1q; Taproot -- SegWit v1 --- addresses start with bc1p, in case you wanted to know the difference; in bech32 q is 0, p is 1)
Now how about HODLers who keep all, or some, of their coins on custodial services? Well, any custodial service worth its salt would be doing at least 2-of-3, or probably something even bigger, like 11-of-15. So your custodial service, if it switched to using Taproot internally, could save a lot more (imagine an 11-of-15 getting reduced from 11 signatures to just 1!), which --- we can only hope! --- should translate to lower fees and better customer service from your custodial service!
So I think we can say, very accurately, that the Bitcoin principle --- that YOU are in control of your money --- can only be helped by Taproot (if you are doing multisignature), and, because P2PKH and P2WPKH remain validly-usable addresses in a Taproot future, will not be harmed by Taproot. Its benefit to this principle might be small (it mostly only benefits multisignature users) but since it has no drawbacks with this (i.e. singlesig users can continue to use P2WPKH and P2PKH still) this is still a nice, tidy win!
(even singlesig users get a minor benefit, in that multisig users will now reduce their blockchain space footprint, so that fees can be kept low for everybody; so for example even if you have your single set of private keys engraved on titanium plates sealed in an airtight box stored in a safe buried in a desert protected by angry nomads riding giant sandworms because you're the frickin' Kwisatz Haderach, you still gain some benefit from Taproot)
And here's the important part: if P2PKH/P2WPKH is working perfectly fine with you and you decide to never use Taproot yourself, Taproot will not affect you detrimentally. First do no harm!

Taproot and Your Contracts

No one is an island, no one lives alone. Give and you shall receive. You know: by trading with other people, you can gain expertise in some obscure little necessity of the world (and greatly increase your productivity in that little field), and then trade the products of your expertise for necessities other people have created, all of you thereby gaining gains from trade.
So, contracts, which are basically enforceable agreements that facilitate trading with people who you do not personally know and therefore might not trust.
Let's start with a simple example. You want to buy some gewgaws from somebody. But you don't know them personally. The seller wants the money, you want their gewgaws, but because of the lack of trust (you don't know them!! what if they're scammers??) neither of you can benefit from gains from trade.
However, suppose both of you know of some entity that both of you trust. That entity can act as a trusted escrow. The entity provides you security: this enables the trade, allowing both of you to get gains from trade.
In Bitcoin-land, this can be implemented as a 2-of-3 multisignature. The three signatories in the multisgnature would be you, the gewgaw seller, and the escrow. You put the payment for the gewgaws into this 2-of-3 multisignature address.
Now, suppose it turns out neither of you are scammers (whaaaat!). You receive the gewgaws just fine and you're willing to pay up for them. Then you and the gewgaw seller just sign a transaction --- you and the gewgaw seller are 2, sufficient to trigger the 2-of-3 --- that spends from the 2-of-3 address to a singlesig the gewgaw seller wants (or whatever address the gewgaw seller wants).
But suppose some problem arises. The seller gave you gawgews instead of gewgaws. Or you decided to keep the gewgaws but not sign the transaction to release the funds to the seller. In either case, the escrow is notified, and if it can sign with you to refund the funds back to you (if the seller was a scammer) or it can sign with the seller to forward the funds to the seller (if you were a scammer).
Taproot helps with this: like mentioned above, it allows multisignature setups to produce only one signature, reducing blockchain space usage, and thus making contracts --- which require multiple people, by definition, you don't make contracts with yourself --- is made cheaper (which we hope enables more of these setups to happen for more gains from trade for everyone, also, moon and lambos).
(technology-wise, it's easier to make an n-of-n than a k-of-n, making a k-of-n would require a complex setup involving a long ritual with many communication rounds between the n participants, but an n-of-n can be done trivially with some moon math. You can, however, make what is effectively a 2-of-3 by using a three-branch SCRIPT: either 2-of-2 of you and seller, OR 2-of-2 of you and escrow, OR 2-of-2 of escrow and seller. Fortunately, Taproot adds a facility to embed a SCRIPT inside a public key, so you can have a 2-of-2 Taprooted address (between you and seller) with a SCRIPT branch that can instead be spent with 2-of-2 (you + escrow) OR 2-of-2 (seller + escrow), which implements the three-branched SCRIPT above. If neither of you are scammers (hopefully the common case) then you both sign using your keys and never have to contact the escrow, since you are just using the escrow public key without coordinating with them (because n-of-n is trivial but k-of-n requires setup with communication rounds), so in the "best case" where both of you are honest traders, you also get a privacy boost, in that the escrow never learns you have been trading on gewgaws, I mean ewww, gawgews are much better than gewgaws and therefore I now judge you for being a gewgaw enthusiast, you filthy gewgawer).

Taproot and Your Contracts, Part 2: Cryptographic Boogaloo

Now suppose you want to buy some data instead of things. For example, maybe you have some closed-source software in trial mode installed, and want to pay the developer for the full version. You want to pay for an activation code.
This can be done, today, by using an HTLC. The developer tells you the hash of the activation code. You pay to an HTLC, paying out to the developer if it reveals the preimage (the activation code), or refunding the money back to you after a pre-agreed timeout. If the developer claims the funds, it has to reveal the preimage, which is the activation code, and you can now activate your software. If the developer does not claim the funds by the timeout, you get refunded.
And you can do that, with HTLCs, today.
Of course, HTLCs do have problems:
Fortunately, with Schnorr (which is enabled by Taproot), we can now use the Scriptless Script constuction by Andrew Poelstra. This Scriptless Script allows a new construction, the PTLC or Pointlocked Timelocked Contract. Instead of hashes and preimages, just replace "hash" with "point" and "preimage" with "scalar".
Or as you might know them: "point" is really "public key" and "scalar" is really a "private key". What a PTLC does is that, given a particular public key, the pointlocked branch can be spent only if the spender reveals the private key of the given private key to you.
Another nice thing with PTLCs is that they are deniable. What appears onchain is just a single 2-of-2 signature between you and the developemanufacturer. It's like a magic trick. This signature has no special watermarks, it's a perfectly normal signature (the pledge). However, from this signature, plus some datta given to you by the developemanufacturer (known as the adaptor signature) you can derive the private key of a particular public key you both agree on (the turn). Anyone scraping the blockchain will just see signatures that look just like every other signature, and as long as nobody manages to hack you and get a copy of the adaptor signature or the private key, they cannot get the private key behind the public key (point) that the pointlocked branch needs (the prestige).
(Just to be clear, the public key you are getting the private key from, is distinct from the public key that the developemanufacturer will use for its funds. The activation key is different from the developer's onchain Bitcoin key, and it is the activation key whose private key you will be learning, not the developer's/manufacturer's onchain Bitcoin key).
So:
Taproot lets PTLCs exist onchain because they enable Schnorr, which is a requirement of PTLCs / Scriptless Script.
(technology-wise, take note that Scriptless Script works only for the "pointlocked" branch of the contract; you need normal Script, or a pre-signed nLockTimed transaction, for the "timelocked" branch. Since Taproot can embed a script, you can have the Taproot pubkey be a 2-of-2 to implement the Scriptless Script "pointlocked" branch, then have a hidden script that lets you recover the funds with an OP_CHECKLOCKTIMEVERIFY after the timeout if the seller does not claim the funds.)

Quantum Quibbles!

Now if you were really paying attention, you might have noticed this parenthetical:
(technical details: a Taproot output is 1 version byte + 32 byte public key, while a P2WPKH (bech32 singlesig) output is 1 version byte + 20 byte public key hash...)
So wait, Taproot uses raw 32-byte public keys, and not public key hashes? Isn't that more quantum-vulnerable??
Well, in theory yes. In practice, they probably are not.
It's not that hashes can be broken by quantum computes --- they're still not. Instead, you have to look at how you spend from a P2WPKH/P2PKH pay-to-public-key-hash.
When you spend from a P2PKH / P2WPKH, you have to reveal the public key. Then Bitcoin hashes it and checks if this matches with the public-key-hash, and only then actually validates the signature for that public key.
So an unconfirmed transaction, floating in the mempools of nodes globally, will show, in plain sight for everyone to see, your public key.
(public keys should be public, that's why they're called public keys, LOL)
And if quantum computers are fast enough to be of concern, then they are probably fast enough that, in the several minutes to several hours from broadcast to confirmation, they have already cracked the public key that is openly broadcast with your transaction. The owner of the quantum computer can now replace your unconfirmed transaction with one that pays the funds to itself. Even if you did not opt-in RBF, miners are still incentivized to support RBF on RBF-disabled transactions.
So the extra hash is not as significant a protection against quantum computers as you might think. Instead, the extra hash-and-compare needed is just extra validation effort.
Further, if you have ever, in the past, spent from the address, then there exists already a transaction indelibly stored on the blockchain, openly displaying the public key from which quantum computers can derive the private key. So those are still vulnerable to quantum computers.
For the most part, the cryptographers behind Taproot (and Bitcoin Core) are of the opinion that quantum computers capable of cracking Bitcoin pubkeys are unlikely to appear within a decade or two.
So:
For now, the homomorphic and linear properties of elliptic curve cryptography provide a lot of benefits --- particularly the linearity property is what enables Scriptless Script and simple multisignature (i.e. multisignatures that are just 1 signature onchain). So it might be a good idea to take advantage of them now while we are still fairly safe against quantum computers. It seems likely that quantum-safe signature schemes are nonlinear (thus losing these advantages).

Summary

I Wanna Be The Taprooter!

So, do you want to help activate Taproot? Here's what you, mister sovereign Bitcoin HODLer, can do!

But I Hate Taproot!!

That's fine!

Discussions About Taproot Activation

almkglor your post has been copied because one or more comments in this topic have been removed. This copy will preserve unmoderated topic. If you would like to opt-out, please send a message using [this link].
[deleted comment]
[deleted comment]
[deleted comment]
submitted by anticensor_bot to u/anticensor_bot [link] [comments]

Fundamental Research about Nano

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Nano we would love the community to discuss Nano in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Nano compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-nano-nano
Or see Nano’s properties directly at its details page:
https://coindecide.com/coindetails/nano-nano
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to nanocurrency [link] [comments]

Fundamental Research about Monero

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Monero we would love the community to discuss Monero in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Monero compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-xmr-monero
Or see Monero’s properties directly at its details page:
https://coindecide.com/coindetails/xmr-monero
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to Monero [link] [comments]

Fundamental Research about Dash

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Dash we would love the community to discuss Dash in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Dash compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-dash-dash
Or see Dash’s properties directly at its details page:
https://coindecide.com/coindetails/dash-dash
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to dashpay [link] [comments]

Some very important points that most people do not understand about Bitcoin

Point 1)
Most people do not understand that you can't send money over internet, but only information. Bitcoin is the first digital settlement layer.
When I send a picture to someone on Facebook messenger, I don't actually send a picture. I send information about the pictures structure, and the picture gets restructured on the client side (the cellphone) of the user I send it to. Copy of the information is being sent, not the picture itself. So you can't send money over internet, it is not possible, only information.
If I have a bank account at some bank, and I send $50 dollars to another person in the same bank by using the banks website, then a transaction happens between two people within the same infrastructure, which is the banks back-end system and database. So the banks system just subtracts $50 dollars from one person and adds $50 dollars to another person. But no money has moved, only information has been edited. But if I send money to someone that uses another Bank, then this bank has its own infrastructure which is independent of the first. So Bank1 tells Bank2 that they have a user that wants to send money to a user of the other bank. So Bank1 subtracts $50 from User1, and Bank2 adds $50 to User2, but now Bank1 owes Bank2 $50, why? Because you can't send money over internet. So they have to settle the difference between them with some kind of a settlement system, (cash, gold or a third party like a central bank). This difference can be the result of many transactions between many users and can be millions of dollars of worth, the settlement can be done periodically for example every 6 months.
With Bitcoin, because of how the system works, it is almost as if you can send value over internet for the first time, even though you don't really send value, you still send information, but since the infrastructure is global, it is like the first example, it is as if the world has (one large bank infrastructure), that is fully automated and which no one controls.
This alone makes Bitcoin extremely valuable, because it is a trust less digital settlement layer which is extremely secure and not dependent on one particular nation or organisation.
Point 2)
There can never be more than 21 million Bitcoin. This is very hard for people to grasp. Because what do you mean there can never be more than 21 million bitcoin? It sounds like a game, such a scam... People do not understand that Bitcoin is not normal software. In normal software the developers can change the code as they want and publish the code when they want. They do not understand that Bitcoin is a software that is not like a normal software. You can't actually change the number even if the number is programmed in. Which of-course most people will deny, because it makes no sense for most people. They do not understand that even though it is theoretically possible to change it, it is practically almost impossible. It is theoretically possible for me to convince half of Sweden to burn half of their money, but practically impossible. Just because something is theoretically possible, doesn't mean that it will happen within a time frame, or even in your lifetime. In order for the 21 million supply to change, most people in the Bitcoin community needs to agree on it, which is practically impossible. Miners have to change to the new protocol and so on. Not going to happen.
When gold treasures were lost in the past, someone else could find them. Gold practically never completely disappears, it is a chemical element. With Bitcoin, once it is lost it is practically lost forever (put aside quantum computing for now and other theoretical unforeseeable events). 21 million is only the upper theoretical limit. Bitcoin will be more and more scarce as time goes by. Gold is not like this. Gold has an inflation rate of 1,5% every year. The reason it is constant is because even if the stock gets bigger, the flow into the stock also gets bigger because of better mining capabilities, so you can look at it as constant inflation of 1.5% every year. With Bitcoin, not only do the stock to flow ratio go up every halvening, and the flow into bitcoin not only decreases with time, but almost goes into negative because of lost coins every year. This is completely insane and people do not understand this. If you combine this almost deflationary nature of Bitcoin with extreme bullish market sentiment then you will realize that no one knows what is going to happen in the future because wrapping your head around all this and to come to a conclusion about the Bitcoin price will make you sound absolutely delusional to most people.
Point 3)
People think that $100,000 bitcoin is wishful thinking and that there is not enough money in the world for Bitcoin to be worth millions of dollars. Which I can assure you is false. Bitcoin can even be worth $50 million dollars per coin, which would make 2 satoshi 1 dollar. Even if one Bitcoin transaction would cost 10 000 Satoshi. You might say, that's not possible, whats the point if one transaction is so expensive. Again, you don't need to actually do a transfer of money, as in the first example of point 1, virtual transactions on bank level can happen, or on Coinbase. You can send 100 satoshi to someone and pay 1 satoshi in fee "on the bank level", not on chain, banks or exchanges then will settle the difference as they want. At least with Bitcoin you have the option to be you own bank, even if that will cost you more, you still have the option. This is already happening in front of your eyes. Banks like Dutch ING, Deutsche bank, are already working on custody services for cryptocurrencies. And even exchanges want to operate as banks and exchanges like Coinbase are working to get license for this. This is already happening and it is the correct move forwards, a mix between the legacy banking system and cryptocurrencies. You can already spend your Bitcoin with Coinbase Visa Card or similar services. Most people are too lazy and stupid to operate like us with their own wallets, it is a fact well known.
In terms of the price, money inflow is not the same as market cap. Take for instance the following simple scenario. I own 100% of the shares of my own company and I decide to sell 10% of the company for 1 million USD, which will value my whole company at 10 million USD, so 1 million flow into my company leads to 10x market cap of 10 million USD. For Bitcoin to have 21 trillion market cap, Bitcoin does not need 21 trillion of money inflow. Bitcoin price is dependent on market sentiment, if the market sentiment is such that very few people want to sell their coins because the price keeps going up then you might have 100x market cap of the money inflow. So 1 billion USD in money inflow translates to 100 billion USD in market cap. The multiplier can be 10x, 2x or 50x, all depends on market sentiment and time period. So an inflow of 10 trillion USD in 10 years might lead to 100 trillion USD market cap of BTC and 5 million USD per Bitcoin.
Bitcoin value have no roof, the price might actually just keep going up and up and up and up and up. We have never had something that is absolutely scarce, and global, and seen as an alternative form of money, when the rest of the world keeps bubbling up. There is no limit on the BTC price because the whole world works with a bubbly system, and the way Bitcoin is price discovered, is a guaranteed insane BTC price in the future. Even $100 million USD per Bitcoin in 50 years before I am dead is possible.
Point 4)
Fiat does not need to die, and Bitcoin does not need to take over in order for Bitcoin to have "ridiculous price". No financial crisis is needed. Actually what you want is things to just continue as they have done in the last 10 years. No too extreme events. Just "small events" here and there. You can't change human nature, it is inevitable. Bitcoin is so ingrained into our world that there is no way back. There will be people with whole Bitcoin, and people without. Just like people with gold and stock investments and real estate, and people without those things. No insane events, this is all normal.
Point 5)
Bitcoin has won as the financial cryptocurrency. No flippening will happen. The only flippening will be with gold and fiat currencies. If I wanted to, I could have developed a system like PayPal in 1 month time, and it would be able to do 5000 transactions per second because I would use MySQL and SSD, but no one would use my service because they would not trust me because they have no idea who I am and what my service is, and there is no one to send money too, so the network is not there. Bitcoin has won because security and network effect is way more important than transactions per second. Transactions per second will be dealt with on bank level, exchange level, or layer 2 solutions. This is already clear to me. Bitcoin has won.
Point 6)
In order to understand Bitcoin and what will happen in the future, you have to be able to see things that are not in front of you. You can't compare Bitcoin to Tulip mania, or even Gold. Because something like Bitcoin has never existed before and you have to think about it's properties and try to understand it with human nature and with how the world works and how everything keeps increasing, and Bitcoin is the thing that does not increase in supply. You will eventually accept the unnatural thought of Bitcoin never stopping going up in value, which is something that is hard to come to terms with, because it feels unnatural, "and it could not possibly be so".
Point 7)
The Gini coefficient of Bitcoin is not a big deal. I used to think that it was unfair that some people had 1,000 BTC, 10,000 BTC, or even 50,000 BTC. And I was afraid that they might dump their coins into the market and crash it. I have now realised that these people are smart people and they think like me, and they won't just dump their whole BTC holding on the market as that might be a very bad move for them. It is like when a majority holder of a company, like Jeff Bezos and Amazon, understands that he can't sell all of his shares in one go as that would effect Amazon stock value too much and would not be smart. It is best to sell when the price goes up, but then when they sell the BTC will just be eaten up by other people, and they will be at a loss in the longer term. And the other thing is that perhaps there is no other smart place to put that fiat money, Bitcoin might just be the best place to keep those amounts of money. Someone with a very large holding has two options. He can either sell his BTC, in which case the price would go down but the Bitcoin would be spread out between potentially thousands of new users, or he might decide to never sell. If he decides to never sell, it is as if those Bitcoins are lost forever and that is good for the Bitcoin price and Bitcoin in general. If he decides to sell then Bitcoin will be divided more equally among many users which is also a good thing for Bitcoin because that increases the network effect, and after he sells he no longer has the power to drive the price down, but now he sits on a very large fiat holding, he might even buy back at a higher price and drive the price higher. I know that if I had 10,000 BTC, I would sell 1,000 BTC and buy a house and a car and whatever I wanted, and sell another 1,000 BTC to diversify into some other assets. And keep 8,000 BTC because I don't know of anywhere else to put that kind of money into good work. I believe in Bitcoin so as an investor it makes sense to keep it here. I probably would never sell because I would never need anything else after the initial 1,000 BTC sell.
Bitcoin is like a black hole that sucks in the Earths monetary resources over time. Most people that bought really early and were smart enough to hold all the way to these prices will only sell what they need to sell and keep the rest in BTC. Some of them might want to speculate and try to time the ATH, only to buy back in with most of the fiat they sold. Which means that even if money goes out of the market, it only goes out of the market temporarily, only to get back in at hopefully lower prices. And so the market grows, and grows and grows over time.
Point 8)
Bitcoin has intrinsic value. When people like Peter Schiff say that gold has intrinsic value because gold can be used in electronics and aviation and therefore gold has value but Bitcoin has no value because it has no intrinsic value, you have to take a pause and do some critical thinking. Can you imagine 16th century pirates looking to find a gold treasure worth an insane amount because they knew gold had value because of electronics and aviation? This is clearly absurd. Gold has been used as money for thousands of years and electronics and aviation was not even a thing 150 years ago. Gold has value because it is globally scarce. Bitcoin is absolutely verifiable scarce. Bitcoin has intrinsic value because of it's monetary policy and because you can carry millions of dollars of value by remembering only 24 words in your head, and carry that value wherever you want and no one can stop you, that is intrinsic value.
People had a hard time understanding that a website like Facebook could be worth billions of dollars, because it was not physical, it was "just a website". Even a website like Google search is not physical and still it has immense value. It is valuable information and it provides a good service, and that has value, it does not have to be physical and tangible.
submitted by 21btc to Bitcoin [link] [comments]

Fundamental Research about VeChain

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about VeChain we would love the community to discuss VeChain in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how VeChain compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-vet-vechain
Or see VeChain’s properties directly at its details page:
https://coindecide.com/coindetails/vet-vechain
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to Vechain [link] [comments]

Fundamental Research about NEO

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about NEO we would love the community to discuss NEO in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how NEO compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-neo-neo
Or see NEO’s properties directly at its details page:
https://coindecide.com/coindetails/neo-neo
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to NEO [link] [comments]

Fundamental Research about Cardano

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Cardano we would love the community to discuss Cardano in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Cardano compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-ada-cardano
Or see Cardano’s properties directly at its details page:
https://coindecide.com/coindetails/ada-cardano
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to cardano [link] [comments]

Fundamental Research about Bitcoin Cash

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Bitcoin Cash we would love the community to discuss Bitcoin Cash in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Bitcoin Cash compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-bch-bitcoincash
Or see Bitcoin Cash’s properties directly at its details page:
https://coindecide.com/coindetails/bch-bitcoincash
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to Bitcoincash [link] [comments]

Fundamental Research about Bitcoin Cash

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Bitcoin Cash we would love the community to discuss Bitcoin Cash in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Bitcoin Cash compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-bch-bitcoincash
Or see Bitcoin Cash’s properties directly at its details page:
https://coindecide.com/coindetails/bch-bitcoincash
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to btc [link] [comments]

Fundamental Research about Waves

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Waves we would love the community to discuss Waves in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Waves compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-waves-waves
Or see Waves’s properties directly at its details page:
https://coindecide.com/coindetails/waves-waves
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to Wavesplatform [link] [comments]

Fundamental Research about EOS

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about EOS we would love the community to discuss EOS in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how EOS compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-eos-eos
Or see EOS’s properties directly at its details page:
https://coindecide.com/coindetails/eos-eos
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to eos [link] [comments]

Fundamental Research about Dogecoin

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Dogecoin we would love the community to discuss Dogecoin in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Dogecoin compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-doge-dogecoin
Or see Dogecoin’s properties directly at its details page:
https://coindecide.com/coindetails/doge-dogecoin
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to dogecoin [link] [comments]

Fundamental Research about Cosmos

There are thousands of financial or social metrics about cryptocurrencies on the internet, but when it comes to fundamental characteristics we are barely able to compare coins with each other. And almost nobody has the time to fundamentally analyse each cryptocurrency out there.
We at CoinDecide.com decided to tackle this problem. Our goal is to establish a research platform which enables comparing cryptocurrencies with each other on a fundamental level. To be able to make correct classifications about Cosmos we would love the community to discuss Cosmos in the context of the key fundamental properties we could identify. Here is the list of those properties:
Essentials
Tokenomics
Origins
Extras
You can find more detailed information about these properties at:
https://coindecide.com/
Further, you can see how Cosmos compares to Bitcoin with the information we already tried to gather as an initial research:
https://coindecide.com/compare/btc-bitcoin-vs-atom-cosmos
Or see Cosmos’s properties directly at its details page:
https://coindecide.com/coindetails/atom-cosmos
Let's use this topic to discuss the fundamental properties listed above. Any input is going to help us improve our information quality (giving sources is very much appreciated).
submitted by coindecide to cosmosnetwork [link] [comments]

Lab - Properties of Hydrocarbons - Bromine Test IMF and Properties of Liquids (4.10) PROPERTIES OF COLLOIDS Laplace properties Properties of dot product

[Quantum computing] harnesses quantum properties to actually factor numbers a lot faster, and that’s the whole core of the security behind RSA encryption. The consequences of this is that our data is not going to be secure anymore if we get a big enough quantum computer. So we’re going to have to do something about it.” ADVERTISEMENT. Quantum computing has recently grabbed headlines as ... Quantum computers have two properties that give them the ability to perform complex calculations at an efficient rate. The first is superpositioning. Traditional computers store information as a series of 0’s and 1’s. Quantum computers, on the other hand, store their data using a set of qubits – superpositions of 0 and 1. The qubits effectively exist in two states at once. When you ... Quantum computers will thrive on the following properties: – * It will use Electrons. This is the lightest basic electricity-charged particle or wave. * Particles can exist in multiple locations at the same time. * Distances do not separate particles, a property also known as entanglement. Owing to the above phenomenon, execution speeds will be a million times faster compared to those ... The emergence of quantum computing machines has grabbed headlines over the past few months as the technology poses a threat to cryptographic algorithms that keep cryptocurrencies, like Bitcoin – as well as the internet at large – secure. The World Economic Forum explains how quantum computers can break current standards of encryption. Quantum computers are surely a Kryptonite for Bitcoin. In specific applications, quantum computers perform way better than traditional supercomputers. However, many encryption technologies are still resistant to quantum computers, and the world needs to develop them before such a computer enters the scene. And that’s the point – there’s no actual quantum computer unveiled yet that can ...

[index] [43270] [12913] [37885] [38110] [7596] [13774] [14384] [19348] [9623] [23802]

Lab - Properties of Hydrocarbons - Bromine Test

A discussion of LDF, dipole-dipole and Hydrogen bonding as it relates to properties of liquids such as surface tension, capillary action, hydrophobicity, wetting action and other properties of ... This video is unavailable. Watch Queue Queue. Watch Queue Queue Solved problems on Laplace inverse. For the Love of Physics - Walter Lewin - May 16, 2011 - Duration: 1:01:26. Lectures by Walter Lewin. Some light quantum mechanics (with minutephysics) - Duration: 22 ... Banking on Bitcoin YouTube Movies. 2017 · Documentary; 1:23:41 . Clean Code - Uncle Bob / Lesson 1 - Duration: 1:48:42 ... John Conway: Surreal Numbers - How playing games led to more numbers than anybody ever thought of - Duration: 1:15:45. itsallaboutmath Recommended for you

#