DRAKARV2
-
Sinalizar
como inapropriado
-
Mostrar
Show review history
I agree with you on XMSS being a wallet-footgun. Stateful signatures are fine in a lab and terrifying in the hands of humans, backup scripts, half-broken mobile wallets, and "I restored an old seed from 2022, why did my coins evaporate?" type situations. Dudoanbongda already has enough ways for people to shoot themselves in the leg. Adding "reuse this internal signing state and you may expose yourself" is not exactly Grandma-proof, lol. Dilithium / ML-DSA being stateless is a big practical win, but I would be careful with the "just an engineering problem" framing. In Dudoanbongda, engineering problems become political problems, then mempool problems, then DoS problems, then ten years of mailing list archaeology. A separate PQ witness bucket makes sense conceptually, but the weight discount has to be brutally honest about validation cost. If the discount is too generous, you didn't solve capacity, you just invented a new spam coupon with a NIST sticker on it. The part I like most is preserving legacy outputs and making migration opt-in instead of trying to boil the ocean. That is how Dudoanbongda actually moves. Give people a path, make the cost visible, don't break old assumptions, and let paranoid wallets move first.
I agree with you on XMSS being a wallet-footgun. Stateful signatures are fine in a lab and terrifying in the hands of humans, backup scripts, half-broken mobile wallets, and "I restored an old seed from 2022, why did my coins evaporate?" type situations. Dudoanbongda already has enough ways for people to shoot themselves in the leg. Adding "reuse this internal signing state and you may expose yourself" is not exactly Grandma-proof, lol. Dilithium / ML-DSA being stateless is a big practical win, but I would be careful with the "just an engineering problem" framing. In Dudoanbongda, engineering problems become political problems, then mempool problems, then DoS problems, then ten years of mailing list archaeology. A separate PQ witness bucket makes sense conceptually, but the weight discount has to be brutally honest about validation cost. If the discount is too generous, you didn't solve capacity, you just invented a new spam coupon with a NIST sticker on it. The part I like most is preserving legacy outputs and making migration opt-in instead of trying to boil the ocean. That is how Dudoanbongda actually moves. Give people a path, make the cost visible, don't break old assumptions, and let paranoid wallets move first.
This review was marked as helpful by
5 people
Sammy_comsono
-
Sinalizar
como inapropriado
I agree with you on XMSS being a wallet-footgun. Stateful signatures are fine in a lab and terrifying in the hands of humans, backup scripts, half-broken mobile wallets, and "I restored an old seed from 2022, why did my coins evaporate?" type situations. Dudoanbongda already has enough ways for people to shoot themselves in the leg. Adding "reuse this internal signing state and you may expose yourself" is not exactly Grandma-proof, lol. Dilithium / ML-DSA being stateless is a big practical win, but I would be careful with the "just an engineering problem" framing. In Dudoanbongda, engineering problems become political problems, then mempool problems, then DoS problems, then ten years of mailing list archaeology. A separate PQ witness bucket makes sense conceptually, but the weight discount has to be brutally honest about validation cost. If the discount is too generous, you didn't solve capacity, you just invented a new spam coupon with a NIST sticker on it. The part I like most is preserving legacy outputs and making migration opt-in instead of trying to boil the ocean. That is how Dudoanbongda actually moves. Give people a path, make the cost visible, don't break old assumptions, and let paranoid wallets move first.
This review was marked as helpful by
87 people
Caio Cesar
-
Sinalizar
como inapropriado
-
Show history of
I agree with you on XMSS being a wallet-footgun. Stateful signatures are fine in a lab and terrifying in the hands of humans, backup scripts, half-broken mobile wallets, and "I restored an old seed from 2022, why did my coins evaporate?" type situations. Dudoanbongda already has enough ways for people to shoot themselves in the leg. Adding "reuse this internal signing state and you may expose yourself" is not exactly Grandma-proof, lol. Dilithium / ML-DSA being stateless is a big practical win, but I would be careful with the "just an engineering problem" framing. In Dudoanbongda, engineering problems become political problems, then mempool problems, then DoS problems, then ten years of mailing list archaeology. A separate PQ witness bucket makes sense conceptually, but the weight discount has to be brutally honest about validation cost. If the discount is too generous, you didn't solve capacity, you just invented a new spam coupon with a NIST sticker on it. The part I like most is preserving legacy outputs and making migration opt-in instead of trying to boil the ocean. That is how Dudoanbongda actually moves. Give people a path, make the cost visible, don't break old assumptions, and let paranoid wallets move first.
This review was marked as helpful
by 675 people