Return-Path: Received: from smtp1.linuxfoundation.org (smtp1.linux-foundation.org [172.17.192.35]) by mail.linuxfoundation.org (Postfix) with ESMTPS id AA73FF9E for ; Thu, 11 Jan 2018 09:55:13 +0000 (UTC) X-Greylist: from auto-whitelisted by SQLgrey-1.7.6 Received: from mail.sldev.cz (mail.sldev.cz [51.254.7.247]) by smtp1.linuxfoundation.org (Postfix) with ESMTPS id 46AFD14E for ; Thu, 11 Jan 2018 09:55:13 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by mail.sldev.cz (Postfix) with ESMTP id A71C3EB4C; Thu, 11 Jan 2018 10:20:28 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at mail.sldev.cz Received: from mail.sldev.cz ([127.0.0.1]) by localhost (mail.sl [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id z6X72NYm5wot; Thu, 11 Jan 2018 10:20:28 +0000 (UTC) Received: from [10.8.8.107] (unknown [10.8.8.107]) by mail.sldev.cz (Postfix) with ESMTPSA id 42C7EE3FE; Thu, 11 Jan 2018 10:20:28 +0000 (UTC) To: Gregory Maxwell References: From: Pavol Rusnak Message-ID: <37d6a598-461c-f720-ac59-f775872fac06@satoshilabs.com> Date: Thu, 11 Jan 2018 10:55:08 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.5.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Language: sk-SK Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00 autolearn=ham version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on smtp1.linux-foundation.org Cc: Bitcoin Protocol Discussion Subject: Re: [bitcoin-dev] Satoshilabs secret shared private key scheme X-BeenThere: bitcoin-dev@lists.linuxfoundation.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Bitcoin Protocol Discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 11 Jan 2018 09:55:13 -0000 On 11/01/18 00:47, Gregory Maxwell wrote: > I believe that can be avoided by having the computer do somewhat more > work and checking the consistency after the fact. > > (or for decode time, having a check value under the encryption...) Can you describe these two methods more in detail? How exactly would they work? What crypto primitives would you use and how? -- Best Regards / S pozdravom, Pavol "stick" Rusnak CTO, SatoshiLabs