🌲 On software carpentry
tl;dr: “Beware of bugs in the above code; I have only proved it correct, not tried it.” –Donald Knuth
🌱 Universal composability (UC)
tl;dr: I wish there was better stuff around than UC for modelling security of cryptosystems.
🆚 Confidentiality on Aptos vs. Arc vs. Canton
tl;dr: This is an incomplete and opinionated take on three different approaches to confidential payments (and beyond).
⭐️ Baby-step giant-step (BSGS) discrete log algorithms
tl;dr: When the discrete log $a$ of $a\cdot G$ is known to lie in a small range $[m)$, the baby-step giant-step (BSGS) algorithm recovers $a$ in $\ceil{\sqrt{m}}$ $\Gr$ additions using only a precomputed table of exactly $\ceil{\sqrt{m}}$ compressed points, trading the $O(1)$ time of the naive $m$-sized lookup table for much less memory.
This p...
🔥 Notes on NEAR's MPC
tl;dr:
The good: Audit went well. Lúcás Meier’s Cait-Sith threshold ECDSA protocol seems like a reasonable, conservative choice.
The bad: Near’s MPC currently works in a 5 out of 8 setting, without any proactive refresh.
Notes
Good
MPC’s configuration is transparent, on-chain $\Rightarrow$ can monitor for suspicious membership changes
“u...
🌲 Groth21 PVSS
tl;dr: Groth’s non-interactive distributed key generation paper[^Grot21e], which uses a novel approximate ZK range proofs to argue correct chunking, but inadvertantly increases share decryption time.
112 post articles, 14 pages.