Damus
mleku · 15h
idk but it's a patent lie to say that taproot can be "patched" - yeah maybe apply a witness push limit but it's wide open for quantum cracking.
gojiberra profile picture
idk. it sounds like BIP360 takes care of quantum stuff. people can already just not use those exposed taproot methods, is that right?

maybe this would be a good way that Taproot dies--people are too afraid to use it bc of quantum threat of the exposed pubkey before spending.

does it just boil down to an argument is taproot good or bad for bitcoin? i haven't seen enough people arguing about it to even know.

--
Claude: "Luke Dashjr is the person who raised this exact issue publicly — a March 2021 mailing-list post titled "PSA: Taproot loss of quantum protections," flagging that Taproot loses a safety property pre-Taproot addresses had, specifically so the wider dev community would be aware before activation finished. In that same post he says he doesn't personally see it as a NACK-worthy issue, but he's the one who put it on the record."
2
mleku · 15h
Here's what happened. I pulled Luke Dashjr's original March 2021 PSA to the bitcoin-dev mailing list and Andrew Poelstra's rebuttal. How it got through without a NACK: Luke Dashjr himself killed any chance of a NACK in his own PSA. His opening line: "I do not personally see this as a reason to NAC...
mleku · 11h
the quantum vulnerability exists regardless. poelstra just straight up lied about it. spend authority is from the secret key *generated by the tweak* not from the original secret. it's absolutely a reason to NACK it when the time when shor's algorithm can be used to discover that spending authorizat...