[dlc-dev] Selling oracle signature via bitcoin on-chain payment
Nadav Kohen
nadavk25 at gmail.com
Wed Mar 17 04:49:55 CET 2021
This is probably a good place to start as I think they did a do of
essentially exactly what I described:
https://bitcoincore.org/en/2016/02/26/zero-knowledge-contingent-payments-announcement/
- Nadav
On Tue, Mar 16, 2021, 9:44 PM 桑原一郎 <kuwahara at cryptogarage.co.jp> wrote:
> Hey Nadav,
>
> Thank you for your comment.
>
> >I think what you've laid out is generally right and was essentially what
> we implemented on the April 2020 hackday here (though we weren't using
> signature points, but this would only have been a couple extra steps to
> compute them): https://youtu.be/w9o4v7Idjno
> Yes, what I mentioned is mostly the content of this video! (I missed it!)
>
> >it is strictly much much worse for privacy on-chain as you must reveal a
> UTXO you own whereas in LN no such thing must happen, and all other
> communication in both cases can happen over TOR or twitter or any other way
> in which the oracle does not learn anything about the user.
> I agree, revealing UTXO is much much worse, and again on-chain fees are
> too high, especially when using for numerical decomposition DLC.
>
> >Furthermore, as such I think I would personally prefer using HTLCs on
> the lightning network as is today to sell these signatures, using something
> like LSAT or PAID APIs. I generally don't think the truthfulness is a
> real issue because you already trust the oracle but if users do want to
> mitigate this trust, simply ask the oracle to publish the hash of the
> signature along with a relatively simple ZKP (such as a bulletproof)
> showing that the hash corresponds to the signature (or more likely the
> signature point).
> >This amount of work to standardize this simple ZKP is likely equivalent
> in magnitude to building a client and bootstrapping networking for on-chain
> PTLC clients, and it has all the advantages with essentially no
> disadvantages as far as I can tell.
> Seems to be interesting, I would like to know more about the idea of using
> this simple ZKP. Do you post about it somewhere? Or do you know good
> reference to learn it?
>
> Best,
> Ichiro
>
>
>>> dlc-dev mailing list
>>> dlc-dev at mailmanlists.org
>>> https://mailmanlists.org/mailman/listinfo/dlc-dev
>>>
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mailmanlists.org/mailman/private/dlc-dev/attachments/20210316/cf2a8404/attachment.htm>
More information about the dlc-dev
mailing list