🔥 Hot take on Aptos vs. Arc vs. Canton confidentiality
tl;dr: A hot take is an incomplete, highly-opinionated, potentially-controversial take.
Here, I give one on three different approaches to confidential payments (and beyond).
🌱 Formal verification in Lean
tl;dr: A bunch of resources I hope to get to.
Resources
Lean game server
Tutorial: Introduction to Formal Verification with Lean (Part 1)
zkLean: A DSL for ZK statement verification
🌲 Baby-step giant-step (BSGS) discrete log algorithms
tl;dr: When the discrete log $a$ of $a\cdot G$ is known to lie in a small range $[m)$, the baby-step giant-step (BSGS) algorithm recovers $a$ in $\ceil{\sqrt{m}}$ $\Gr$ additions using only a precomputed table of exactly $\ceil{\sqrt{m}}$ compressed points, trading the $O(1)$ time of the naive $m$-sized lookup table for much less memory.
This p...
🔥 Notes on NEAR's MPC
tl;dr:
The good: Audit went well. Lúcás Meier’s Cait-Sith threshold ECDSA protocol seems like a reasonable, conservative choice.
The bad: Near’s MPC currently works in a 5 out of 8 setting, without any proactive refresh.
Notes
Good
MPC’s configuration is transparent, on-chain $\Rightarrow$ can monitor for suspicious membership changes
“u...
🌲 Groth21 PVSS
tl;dr: Groth’s non-interactive distributed key generation paper[^Grot21e], which uses a novel approximate ZK range proofs to argue correct chunking, but inadvertantly increases share decryption time.
🌱 TIL: Malleable algebraic NIZKs
tl;dr: This is a “note to self” that there’s some interesting work out there on malleable NIZKs[^CH20]$^,$[^DaEFplus23e].
108 post articles, 14 pages.