00:07:46 breesy has quit 00:55:24 CodeShar_ has joined #bitcoin-wizards 00:58:07 CodeShark has quit 01:04:02 CodeShar_ has quit 01:04:33 CodeShark has joined #bitcoin-wizards 01:05:44 Emcy has quit 01:06:18 Emcy has joined #bitcoin-wizards 01:06:19 Emcy has quit 01:06:19 Emcy has joined #bitcoin-wizards 01:44:58 zooko has joined #bitcoin-wizards 01:46:43 Ursium has quit 01:58:31 Ursium has joined #bitcoin-wizards 02:59:05 fractastical has quit 03:05:16 zooko has quit 03:07:36 shinybro_ has joined #bitcoin-wizards 03:08:42 shinybro__ has joined #bitcoin-wizards 03:09:22 shinybro has quit 03:11:56 jtimon has quit 03:42:29 spin123456 has joined #bitcoin-wizards 03:42:29 spinza has quit 03:46:28 amincd has quit 03:50:37 rdymac has quit 03:55:33 rdymac has joined #bitcoin-wizards 04:08:36 Luke-Jr has quit 04:14:09 jrmithdobbs has quit 04:15:50 pajarillo has quit 04:16:45 jrmithdobbs has joined #bitcoin-wizards 04:23:23 Luke-Jr has joined #bitcoin-wizards 04:24:37 pajarillo has joined #bitcoin-wizards 04:27:23 Luke-Jr has quit 04:29:16 Luke-Jr has joined #bitcoin-wizards 04:36:56 wallet42 has quit 04:46:58 Luke-Jr has quit 04:48:42 Luke-Jr has joined #bitcoin-wizards 04:58:06 cpacia has quit 05:19:03 fractastical has joined #bitcoin-wizards 06:02:32 freewil has joined #bitcoin-wizards 06:07:29 shinybro__ is now known as shinybro 06:21:03 e4xit has quit 06:25:22 tromp_ has quit 06:25:45 tromp has joined #bitcoin-wizards 06:43:25 e4xit has joined #bitcoin-wizards 07:01:49 gmaxwell, tripping dem 220 amp breakers 07:01:51 is hilarious 07:02:43 * gmaxwell loans phantomcircuit an amp meter 07:03:02 gmaxwell, it's all 3 phase 07:03:09 it's unpossible to get them to balance right 07:03:13 shit is super annoying 07:03:36 and of course all the plugs are ac so the meter has to be inline 07:05:39 gmaxwell, i wish i could buy split ac cables in bulk 07:05:44 you're running the gear @208 right? rotating pairs should get them balanced so long as the number in the rack is a multiple of 3. 07:05:47 but they cost like 4x as much as a normal cable 07:06:20 gmaxwell, sure except the two psu's dont pull the same for all the boxes 07:06:26 ugh 07:06:42 im probably going to end up having to measure each individual box and match them up 07:06:46 it's gonna be terrrible 07:07:16 phantomcircuit: on my avalons and ants I was balancing the power on my two legs (I have some problem with my neutral here— it has high resistance or something)— by twiddling the clockrates. 07:07:54 gmaxwell, yeah except on the cointerra stuff the frequency scaling stuff is for both boards 07:08:08 (they can actually be controlled individually but not easily yet) 07:08:20 (If I put too much load on one leg the voltage on it sags, and the voltage on the other side goes up ... 130v uhhh no thanks) 07:08:37 hehehe 07:09:12 at least for right now im just going to try and spread them out 07:09:22 at least we have the space ... 07:09:38 one miner per rack.. :P 07:10:01 you jest but i actually do have 3 racks with 1 miner 07:10:11 was just to measure them but... well i left them there 07:21:29 nessence has quit 07:56:29 lnovy has quit 07:59:55 lnovy has joined #bitcoin-wizards 08:04:16 adam3us has joined #bitcoin-wizards 08:04:25 lnovy has quit 08:04:56 lnovy has joined #bitcoin-wizards 08:12:31 adam3us has quit 08:27:33 RBRubicon has joined #bitcoin-wizards 08:35:37 Guest6827 has quit 08:51:50 nOgAnOo has quit 09:05:09 shinybro has quit 09:06:33 nOgAnOo has joined #bitcoin-wizards 09:36:17 oyjvnkk has joined #bitcoin-wizards 09:41:55 airbreather has quit 09:44:20 fanquake has joined #bitcoin-wizards 09:54:31 airbreather has joined #bitcoin-wizards 09:56:17 <_ingsoc> _ingsoc has joined #bitcoin-wizards 09:57:54 swulf-- has joined #bitcoin-wizards 10:00:24 BlueMatt has quit 10:01:51 roconnor_ has joined #bitcoin-wizards 10:02:07 BlueMatt has joined #bitcoin-wizards 10:04:14 roconnor has quit 10:21:14 <_ingsoc> _ingsoc has quit 10:23:56 MoALTz has joined #bitcoin-wizards 10:34:48 orperelman has joined #bitcoin-wizards 10:40:16 swulf-- has quit 10:59:23 swulf-- has joined #bitcoin-wizards 11:09:07 fractastical has quit 11:12:50 swulf-- has quit 11:25:55 nOgAnOo has quit 11:36:25 nOgAnOo has joined #bitcoin-wizards 11:36:52 aksyn has quit 11:39:40 aksyn has joined #bitcoin-wizards 11:41:30 RBRubicon has quit 11:42:14 orperelman has quit 11:51:02 oyjvnkk has quit 12:04:27 go1111111 has quit 12:08:13 RBRubicon has joined #bitcoin-wizards 12:08:26 fanquake has left #bitcoin-wizards 12:10:51 <_ingsoc> _ingsoc has joined #bitcoin-wizards 12:14:26 RBRubicon has quit 12:39:49 jtimon has joined #bitcoin-wizards 12:59:58 RBRubicon has joined #bitcoin-wizards 13:10:29 rdymac has quit 13:15:30 optimator has quit 13:15:49 optimator has joined #bitcoin-wizards 13:18:46 grazs is now known as grzs 13:29:21 nOgAnOo has quit 13:31:01 jtimon has quit 13:35:30 jtimon has joined #bitcoin-wizards 13:42:43 zooko has joined #bitcoin-wizards 13:45:45 jgarzik is now known as home_jg 13:48:12 c--O-O has quit 13:48:32 orperelman has joined #bitcoin-wizards 13:50:00 mike4 has joined #bitcoin-wizards 13:54:50 mike4 is now known as c--O-O 13:54:58 c--O-O has quit 13:54:58 c--O-O has joined #bitcoin-wizards 13:54:58 c--O-O has quit 13:54:58 c--O-O has joined #bitcoin-wizards 13:56:09 shinybro_ has quit 14:06:35 Hey wizards: Question: if we change bitcoind's change creation algorithm so that, if there is enough change, it produces two change outputs: one matching the payment amount, and one with the rest… would that help, hurt, or have no effect on privacy, assuming "typical" payment patterns, later payment of transaction fees, etc. If it hurts, is there a simple variation that would help? 14:06:56 The goal for creating more change outputs is to make it more likely there are confirmed inputs to use in subsequent transactions. 14:07:18 to make sure sufficient outputs exist, i would suggest splitting the change in two (approximately) rather than matching the input 14:07:57 though matching the actual output is interesting for privacy 14:09:10 aksyn has quit 14:12:18 Oh, and a meta-question: are any of you plugged into the academic work being done on bitcoin transaction privacy? Would any academics be interested in helping with this kind of "small ball" incremental improvements, as opposed to coming up with Theoretically Perfect solutions? 14:20:37 aksyn has joined #bitcoin-wizards 14:23:07 rdymac has joined #bitcoin-wizards 14:27:44 MoALTz has quit 14:28:11 hey, sipa, what's the status of secp256k1? 14:28:28 MoALTz has joined #bitcoin-wizards 14:28:28 any hope of merging it into bitcoind? or perhaps getting those optimizations implemented in popular crypto libs? 14:29:26 CodeShark: yes, it may be merged after 0.9 14:29:32 as an experimental mode 14:30:09 freewil has quit 14:30:18 so a compile-time switch? or a runtime-switch? 14:30:28 compile time 14:32:47 MoALTz has quit 14:33:06 apparently someone tried using boost::multiprecision as a backend for it 14:33:14 are you aware of it? 14:33:17 no 14:33:24 blockchain is down :S 14:33:52 good, learn to deal with not being able to rely on a centralized service 14:34:12 just wondering why it's down 14:34:37 try asking them - not sure anyone here will have the answer :) 14:38:25 just thought you would be interested in the situation 14:40:24 depends on whether the situation is caused by routine web server maintenance or by a coordinated attack 14:40:55 the former is more likely :) 14:41:49 there's a very good chance it's the type of problem that goes away as soon as the web server gets restarted :) 14:47:30 Ursium has quit 14:49:27 Taek42 has joined #bitcoin-wizards 14:55:26 orperelman has quit 15:24:22 roidster has joined #bitcoin-wizards 15:24:38 roidster is now known as Guest45917 15:33:16 jgarzik has joined #bitcoin-wizards 15:33:16 jgarzik has quit 15:33:16 jgarzik has joined #bitcoin-wizards 15:35:30 Guest45917 has quit 15:36:49 RBRubicon has quit 16:08:40 jedunnigan has joined #bitcoin-wizards 16:08:57 roidster has joined #bitcoin-wizards 16:09:54 jedunnig_ has joined #bitcoin-wizards 16:14:08 jedunnigan has quit 16:17:21 Emcy has quit 16:17:28 Emcy has joined #bitcoin-wizards 16:21:09 austinhill has quit 16:25:31 zooko has quit 16:25:50 oleganza has joined #bitcoin-wizards 16:25:55 samesong has joined #bitcoin-wizards 16:26:45 hey guys. I have a proposal for blind ECDSA signatures compatible with Bitcoin txs http://oleganza.com/blind-ecdsa-draft-v1.pdf 16:27:01 the idea is to lock your valuable stash with 5-of-9 multisig tx with your friends. 16:27:30 and when need to sign it, use blind signatures, so your friends do not find out which transaction they signed and how much money you have 16:27:43 DougieBot5000 has joined #bitcoin-wizards 16:28:28 unlike SSSS or DH-like tricks, there's never a point in time when all precious secrets are stored on a single machine (because it may be compromised). 16:29:02 i opened a discussion on bitcointalk too: https://bitcointalk.org/index.php?topic=440572.0 16:34:15 tromp_ has joined #bitcoin-wizards 16:36:51 tromp has quit 16:40:53 shaman_ua has joined #bitcoin-wizards 16:41:26 oleganza: exciting, i will review this 16:41:54 andytoshi: thanks 16:52:21 andytoshi: i'm not often online in IRC. Feel free to comment via email oleganza@gmail.com or twitter @oleganza 16:53:33 oleganza: cool, i'll send you an email 16:57:04 han835 has joined #bitcoin-wizards 16:57:04 han835 has quit 17:09:30 vdo has joined #bitcoin-wizards 17:12:49 adam3us has joined #bitcoin-wizards 17:14:23 zooko has joined #bitcoin-wizards 17:14:59 fract4l has joined #bitcoin-wizards 17:19:51 OneFixt_ has joined #bitcoin-wizards 17:21:20 OneFixt_ has quit 17:21:42 OneFixt_ has joined #bitcoin-wizards 17:23:53 OneFixt has quit 17:26:23 OneFixt_ is now known as OneFixt 17:29:18 vdo has quit 17:34:12 anyone here familiar with openCL and PoW's? I'd like to pay a $1500 bounty for a some work 17:34:24 msg me 17:36:24 fractastical has joined #bitcoin-wizards 17:36:56 flotsamuel has joined #bitcoin-wizards 17:41:33 shaman_ua has quit 17:43:35 oleganza has quit 17:46:54 fract4l has quit 17:47:53 fractastical has quit 17:47:55 jtimon has quit 17:51:49 han_ has joined #bitcoin-wizards 17:56:38 e4xit has quit 17:56:57 e4xit has joined #bitcoin-wizards 18:00:42 jedunnigan has joined #bitcoin-wizards 18:01:04 fractastical has joined #bitcoin-wizards 18:01:57 flotsamuel has quit 18:04:01 jedunnig_ has quit 18:17:31 Manfred_Karrer has joined #bitcoin-wizards 18:19:58 shaman_ua has joined #bitcoin-wizards 18:21:41 RBRubicon has joined #bitcoin-wizards 18:31:40 samesong has quit 18:32:08 samesong has joined #bitcoin-wizards 18:33:34 han_ has quit 18:33:55 spin123456 has quit 18:36:59 spinza has joined #bitcoin-wizards 18:50:13 oleganza has joined #bitcoin-wizards 18:54:56 zooko has quit 18:55:52 roidster has quit 18:56:24 roidster has joined #bitcoin-wizards 18:57:51 roidster has quit 18:59:58 RBRubicon has quit 19:02:55 iddo has quit 19:03:04 iddo has joined #bitcoin-wizards 19:05:03 jgarzik_ has joined #bitcoin-wizards 19:08:11 jgarzik has quit 19:14:13 jgarzik_ has quit 19:16:36 jedunnigan has quit 19:19:31 Ursium has joined #bitcoin-wizards 19:22:16 samesong has quit 19:30:39 jgarzik has joined #bitcoin-wizards 19:33:13 samesong has joined #bitcoin-wizards 19:37:51 what are people's thought on how large/complex scripts ought to be paid for in principle with flexable scripting mechanism? 19:44:41 shaman_ua has quit 19:46:21 zooko has joined #bitcoin-wizards 19:46:24 everyone pays for them :/ 19:47:25 oleganza has quit 19:48:06 Luke-Jr has quit 19:48:26 Luke-Jr has joined #bitcoin-wizards 19:52:15 imho, the only way that aligns miner's incentives with relaying, is by enforcing a consensus-rule limit on the expensive part 19:52:52 so if CPU time is to be limited, define some unit for measuring it, and put a limit on per-block computations 19:53:09 so miners have an incentive to optimize for fee per operation 19:53:21 roconnor_: miners dont incur the costs of expensive scripting 19:58:52 shaman_ua has joined #bitcoin-wizards 19:58:54 I feel a little uncomfortable with an arbitrary per-block limit 20:01:40 Though I suppose if scripts are made only an ephemeral part of the block chain (by not letting them influence hashes) most nodes can eventually discard them, and only archive nodes need to keep them around. 20:01:49 <_ingsoc> _ingsoc has quit 20:02:15 <_ingsoc> _ingsoc has joined #bitcoin-wizards 20:04:18 roconnor_: though its useful to think carefully about the security and incentive model change that implies... it suggests you won't validate past a certian depth, so a moderate sized reorg can be rewarded with stolen funds. 20:05:55 sipa: I'm thinking of designing a scripting system based on the linear (or rather affine) lamba calculus without exponentials with the script hash being a merkle hashing of the abstract syntax. I believe the affine lambda calculus brings code side and execution time together. 20:06:12 oleganza has joined #bitcoin-wizards 20:06:16 gmaxwell: why does it suggest I won't validate past a certain depth (any more than bitcoin suggests). 20:07:13 *code size and execution time 20:07:18 roconnor_: because if you don't never have the data you can't verify it. Unless I misunderstood you. Not having it influence the hashes sounded like you intended to never fetch it. 20:07:35 RBRubicon has joined #bitcoin-wizards 20:08:22 In bitcoin we support that as a reduced security model— SPV— but just for end clients (and you don't need to prevent it from influencing hashes to get that). having the whole system have SPV security past some depth may well be a worthwhile tradeoff, but its not one to take likely. 20:08:27 er lightly. 20:08:31 gmaxwell: my thinking is that a transaction is not valid without *some* signature but that signature doesn't influce the the hash of the transaction, block, or blockchain in any way. 20:09:32 (my type theory hat says the type of signatures is squashed) 20:10:47 as in all valid signatures are considered equivalent and can be substituted for each other in any context. 20:11:08 which in turn implies that hashing cannot depend on the exact nature of the signature. 20:14:51 samson_ has quit 20:16:37 roconnor_: you may or may not know, people have been discussing merjleized abstract syntax here for a while (which were your idea, iirc) :) 20:18:16 *merkleized 20:18:46 has anyone made notes on merkel AST ideas that you know of? 20:19:07 i read through the paper oleganza posted here earlier, it looks legit 20:19:21 blind-ecdsa-draft? 20:19:22 (re blind ecdsa sigs, completely unrelated to this convo, sorry) 20:19:52 andytoshi: thanks. I'm reading through your email 20:20:02 oh 20:20:09 oleganza: did you solve the distingushable nonce problem? 20:20:14 yep 20:20:18 \O/ 20:20:22 spin123456 has joined #bitcoin-wizards 20:20:22 spinza has quit 20:20:34 gmaxwell: i've also posted link here: https://bitcointalk.org/index.php?topic=440572.0 20:20:39 http://oleganza.com/blind-ecdsa-draft-v1.pdf 20:20:55 could someone summarize the distinguishable nonce problem? 20:20:59 the solution is pretty bruteforce: just linearly transform everything and then deduce none and public key from there 20:20:59 * nsh starts reading the paper 20:21:18 gmaxwell: the blind signer doesn't use ecdsa proper, it's pretty slick 20:21:29 nsh: "distinguishable nonce" comes from my first incorrect idea: https://bitcointalk.org/index.php?topic=440572.0 20:21:44 but the result (after the message owner does a bit of manipulation) is a valid ecdsa signature 20:21:59 s/none/nonce/ 20:22:44 does this demonstrate ecdsa malleability? 20:22:53 nsh: it proves that ECDSA is broken 20:22:56 nsh: please don't confuse one of the founders of public-key cryptography with the prime minister of germany 20:23:01 nsh: i'm working with some of the guys on #concatenative to put together a merkelized forth/joyscript proposal 20:23:10 heh 20:23:27 maaku, cool. thanks 20:23:58 i don't know, I think Ralph Merkle could do a better job as chancellor 20:24:01 sipa, oops :) 20:24:23 samson_ has joined #bitcoin-wizards 20:24:42 maaku: who knows! 20:25:00 unsure about making Angela Merkel design cryptographic constructs, though... 20:26:08 i think she has a quantum physics/chemistry background, so her math might not be that bad, relatively speaking... 20:26:13 nsh: it has kinda been low priority though, but I have gotten a lot of people interested in it at least 20:26:22 * nsh nods 20:26:23 oleganza: oh. hm! this achieves a somewhat different notion of blinding than typical, I think. I don't think I could convince the public that bob was a blindsigner on this without revealing data that would allow bob to know exactly which instance of his signing that we're talking about. 20:26:52 oleganza: sorry, i won 20:26:59 oleganza: sorry, i won't have time to read it today 20:27:02 really? heh that's what Merkle does these days (quantum chemistry simulations) 20:27:32 it's a conspiracy! 20:27:36 gmaxwell: that's a good point. what's neat here is that with bitcoin you don't need to convince the public that bob is the signer, you just have to trust bob (because in oleganza's usecase you hope he'll be an escrow agent for you) 20:27:40 ( "Investigation of the mechanism of decay reactions with single bond breaking and calculation of their velocity constants on the basis of quantum chemical and statistical methods" - http://en.wikipedia.org/wiki/Angela_Merkel#cite_note-22 ) 20:27:44 angela merkel and ralph merkle are like Jekyll and Hide 20:28:09 andytoshi: well I have usecases too, my friend! 20:28:21 I want blind signing in bitcoin for anti-doublespend oracles for instant payments. 20:28:25 :P 20:28:27 gmaxwell: yep, it's more specific to my use case. 20:28:33 :P ok that's a better one 20:28:34 gmaxwell: tell us more about your use cases 20:28:43 oleganza: maybe we can figure out how to get public verifiability 20:29:01 well, good to have things in any case even if you don't get full blind signing. 20:29:29 austinhill has joined #bitcoin-wizards 20:29:38 andytoshi: do you have a concrete example of when it might be useful? 20:30:04 oleganza: sure, in the chaum bank example you cited you want the public to be able to verify that your token is signed by the bank 20:30:42 without having to ask the bank to reveal any secret key material 20:32:54 shaman_ua has quit 20:33:22 it's also not clear to me what the danger of revealing or reusing some parameters, though i'll do some analysis on that. this is part of why i mentioned in the email that you should simplify the protocol discription, i think you could get it to a point where you can just "see" what the security requirements for each parameter are 20:36:10 jgarzik has quit 20:40:01 Ursium has quit 20:41:03 samesong has quit 20:42:01 jedunnigan has joined #bitcoin-wizards 20:43:38 jedunnig_ has joined #bitcoin-wizards 20:46:29 Alanius has quit 20:47:21 jedunnigan has quit 20:47:39 jedunnigan has joined #bitcoin-wizards 20:47:56 jedunnigan has quit 20:48:08 jedunnig_ has quit 20:48:58 Alanius has joined #bitcoin-wizards 20:50:25 roidster has joined #bitcoin-wizards 20:54:41 oleganza has quit 20:54:58 oleganza has joined #bitcoin-wizards 20:55:48 Ursium has joined #bitcoin-wizards 20:56:47 fractastical has quit 20:56:49 oleganza has quit 21:04:04 samesong has joined #bitcoin-wizards 21:09:24 samesong_ has joined #bitcoin-wizards 21:10:55 samesong has quit 21:13:30 oleganza has joined #bitcoin-wizards 21:14:15 RBRubicon has quit 21:19:02 samesong has joined #bitcoin-wizards 21:20:35 orperelman has joined #bitcoin-wizards 21:20:59 samesong_ has quit 21:25:38 <_ingsoc> _ingsoc has quit 21:28:45 fractastical has joined #bitcoin-wizards 21:29:36 rdymac has quit 21:31:18 eristisk has joined #bitcoin-wizards 21:34:37 rdymac has joined #bitcoin-wizards 21:35:07 freewil has joined #bitcoin-wizards 21:35:27 freewil has quit 21:42:38 jtimon has joined #bitcoin-wizards 21:43:52 shaman_ua has joined #bitcoin-wizards 21:46:43 shaman_ua has quit 22:10:26 samson_ has quit 22:10:39 austinhill has quit 22:18:02 andytoshi: thanks for your comments, will improve and send you draft 2 soon. 22:18:57 andytoshi: yes, some parameters I think could be reused. As I said, my approach wasn't very elegant, so I probably have too many parameters floating around. 22:24:39 orperelman has quit 22:25:22 http://www.coindesk.com/mt-gox-may-headed-bankruptcy/ < wow someone pointed out that solvency can be proven in an article addressed to a general audience! 22:27:04 jtimon has quit 22:27:07 gmaxwell: i get when bitcoiners get sarcastic about perceived weakness in the protocol (because they can prove that it's not broken), but when it's about opaque third party with shitty PR and a big history of problems, then I don't get sarcasm 22:27:21 disclosure: was never user of mtgox and don't really care what's going on there. 22:27:33 I'm not being sarcastic. 22:27:42 I think its great that it was pointed out there. 22:27:55 ah, ok 22:28:06 I think we _should_ be demanding cryptographic proof from these providers. 22:28:11 gmaxwell: i just remembered that your were buying goxcoins 22:28:16 They won't provide it unless the public demands it. 22:28:28 so i wonder how you know that they are alright 22:28:30 oleganza: yea, well I totally regret that now. I feel like I was mislead by magicaltux. 22:28:38 jtimon has joined #bitcoin-wizards 22:29:20 i thought it was less than a week ago you were buying goxbtc? what did change? 22:30:16 over a week ago— their press release. As I wrote about publically I understood their original issues (having brought some of them to their attention!) 22:31:03 gmaxwell: I myself was shocked when I discovered that some long-time bitcoiners who studied it pretty deep, were keeping all of their BTC on Gox. 22:31:12 I believed their losses were small, since /obviously/ it wouldn't have been people like phantomcircuit and myself telling them they had problems if they were really hemorrhaging coin. Right ??? ... 22:31:31 oleganza: well I never keep my coin in third party hands beyond what is strictly needed. 22:31:51 gmaxwell: i think so. I meant other guys 22:32:26 a friend of mine has a little bit of BTC and stores on bitcoin-central. But he is not willing to study it deep and thinks it's a toy. So i don't blame him. 22:32:35 gmaxwell, i would be very *very* surprised if they were insolvent 22:32:47 What I don't understand is how other guys, who study BTC quite deep, still hold coins in one exchange 22:32:48 well obviously they aren't broke. 22:32:50 (not the least of which is the technical definition of solvency requires written demands...) 22:33:26 I went and bought some goxcoin undercutting the market in part because I was a bit pissed that other people buying it were going around spreading FUD out of one side of their mouth and then buying up the coins with the other. oh well. The press release caught me completely off guard, I didn't anticipate it so, obviously my initial assesments were all off. 22:33:56 fortunately I don't have most of my coins there now or anything insane like that, but I do have wwwayyyyy more than I'm comfortable with having there. 22:34:46 gmaxwell: funny. To me Gox was always so incredibly complicated to get into, I waited till December 2012 to do wire transfers directly to Bitcoin-Central. Was fast, easy and simple. 22:34:58 so never touched gox in my life 22:35:06 oleganza: i have a significant amount on mtgox... why? it was once a tiny amount (~2 years ago), and i had never bothered to get verified (at the time that wasn't necessary) 22:35:13 oleganza, december 2012 is a long time ago 22:35:14 sipa: doh! 22:35:21 (didn't realize you hadn't gotten verified) 22:36:22 oleganza: I've periodicaly sold coin for USD there, simply because the prices were quite high— enough that the quiet 5% manual processing fee to actually get USD out still left me ahead. 22:36:59 e.g. I sold some coin there for over $1000/btc a few weeks ago. 22:40:11 phantomcircuit: I learned about BTC (second time) in August 2012 and purchased some coins through a friend with paypal leftovers in October 2012 (because mtgox was impossibly complicated to get into) 22:40:34 then I learned about super-kosher Bitcoin-Central (about that time there were news about it having all licenses and stuff) 22:40:51 lol 22:40:54 since I'm in Paris with french bank account, it was very easy just to make a wire transfer 22:41:21 they were an agent of a a payment services directive authorized company, which is in turn an agent of a bank, which in turn operates under a charter from the french central bank 22:41:42 heh, when i last actually used mtgox, the exchange rate was like $6, and fees + withdraw fee + conversion to euro altogether was at most a few % loss 22:41:47 oleganza, that is quite literally the lowest form of authorization to operate that it's even possible to obtain 22:42:00 (an agent of a psd cannot allow another party to act as their agent) 22:43:20 phantomcircuit: well, I was only studying btc that time and didn't really care about these details - i was never going to have long-term relationship with their vaults 22:44:50 blargh 22:44:56 ovh has yet another new control panel 22:45:04 and about 50% of it isn't translated 22:53:32 cpacia has joined #bitcoin-wizards 22:56:00 gmaxwell: where can i read more about "anti-doublespend oracles for instant payments" 22:58:00 oleganza: I dunno, I've pointed out in a couple places. The idea is similar to your multisignature. Except the 'friend' is trusted by the world to never sign with a key more than twice. The first signature you use to get them to sign a timelocked refund. When you go to buy something from someone you pay them using the other signature, and show them the refund— they're happy that the refund doesn't unlock for a couple weeks, and ... 22:58:06 ... thus its impossible for you to double spend them. If the oracle cheats, the extra signatures can be made public, etc. 22:58:31 Now, it's best if the oracle is maximally blinded otherwise— so that it can't selectively deny service or be easily ordered not to serve some people.. and can't track people's transactions. 22:59:12 gmaxwell: good point 22:59:33 gmaxwell: i had such idea for a "template server" to fix the problem with storing unencrypted keys on the server 22:59:43 for micro-transactions used to pay for API usage to other servers 23:00:33 the problem is: if you want to put some cash on your web 2.0 app server, so it pays Amazon or Yahoo, that cash can be stolen by someone sneaking in the datacenter 23:01:40 samesong has quit 23:02:35 so you can lock your cash in 2-of-3 multisig tx. One key will unencrypted on your webserver, another one - on 3rd party "template signer" server and 3rd key - emergency key for yourself (in case 3rd party disappears) 23:03:16 normally, your webserver will sign txs with its key and using "template server" which will be allowed to automatically sign txs matching predefined rules ("templates") 23:03:40 so you can say "only authorize txs to these addresses and not more than X BTC per 24h" 23:03:52 then, the cryptographic part is cool 23:03:58 you take the file with those rules 23:03:59 hash it 23:04:28 right and the rules give you the key. 23:04:37 multiply hash(rules) by a single well-known pubkey of the template server 23:04:37 and use it as your pubkey for these rules 23:04:40 H(rules) + oracle_key = real key. 23:04:51 so you can prove if the server signed some tx incorrectly 23:05:08 and their single pubkey will become invalid in the eyes of everyone 23:05:10 yea, I think every oracle idea I've talked about has done that kind of pay to contract approach. I'm fond of it too— no ambiguity. Though also no denyability which is a little unfortunate. 23:05:14 (at times) 23:05:35 but here, by design, signatures should not be blind - because server matches tx with the rules 23:06:02 i doubt you can have rule-matching and deniability at the same time :) 23:06:21 although, even there it would be _nice_ if only the rules were proven, not the txn content. Implementing that requires fancier things, however. 23:06:26 You absolutely can. 23:06:35 it's just Fancy(tm). 23:06:43 like homomorphic encryption? 23:06:51 not that fancy. :) 23:06:55 samesong has joined #bitcoin-wizards 23:06:58 then i'm curious 23:07:01 how fancy? 23:07:15 You have the signee do a (potentially) interactive zero-knoweldge proof with the signer that convinces them the thing you want blindly signed meets the rules. 23:07:46 ah, i heard about that 23:07:54 idea: if you want blind signatures for oracle only to disallow selected censorship, then it's easy to fix 23:08:27 ask oracle to "accept" a tx hash first, so you can prove to anyone that they were "ready to sign it", then ask to sign the tx itself with all its content open. 23:08:48 systems that can do this with basically pratical performance have been implemented now, see the pinocchio paper. It's not as crazy as fully homomorphic encryption, but its still rocket sciency. 23:09:06 oleganza: yes, thoug thats only after the fact which is a little annyoing, and they can still track. 23:09:07 so if they decline signing tx based on its content, you can show that they are censoring 23:09:20 gotta go 23:09:24 TTYL. 23:09:29 was great chatting with you guys 23:10:38 fractastical has quit 23:12:17 interestingly, if you have scalable threshold signatures, ZKP for script acceptance, and blind signing you can damn near completely outsource script... which is kinda interesting. 23:14:17 zooko has quit 23:15:03 Ursium has quit 23:15:22 samson_ has joined #bitcoin-wizards 23:21:02 gmaxwell: so you can have ethereum on bitcoin right away 23:21:53 oh sure, well oracles can give you that _now_ (after all ethereum isn't ZK) ... this is one of the reasons that I'm skeptical about claims of ethereum's value. people are hardly using whats already internal, and you can already do turing complete external scripts with oracle multisignature. 23:22:07 e.g. 3 of 5 oracles to control a spend, or what have you. 23:22:40 It would be _better_ with scalable threshold crypto though, so then you could have 51 of 100 oracles or what have you. ... but it's certantly possible now. 23:23:31 spinza has joined #bitcoin-wizards 23:26:11 jarpiain_ has quit 23:26:40 jarpiain has joined #bitcoin-wizards 23:26:59 spin123456 has quit 23:27:04 jarpiain is now known as Guest17836 23:33:11 breesy has joined #bitcoin-wizards 23:34:00 oleganza has quit 23:38:56 samesong has quit 23:42:43 freewil has joined #bitcoin-wizards 23:44:46 c0rw1n has joined #bitcoin-wizards 23:44:48 samesong has joined #bitcoin-wizards 23:45:21 c0rw1n is now known as c0rw|zZz 23:56:39 lnovy is now known as ` 23:56:48 <`> ` is now known as lnovy