35 ms·
One important weakness of zkSnarks is that it requires a trusted setup, for example [1]. A new alternative is called zk-STARK [2], which doesn't require the tru
by CalmStorm 6y ago
One important weakness of zkSnarks is that it requires a trusted setup, for example [1]. A new alternative is called zk-STARK [2], which doesn't require the trusted setup, and is post-quantum secure. However, it significantly increases the size of the proof (around ~50KB). In general, hash-based post-quantum algorithms require bigger size and it would be interesting to watch the progress made in this regard.
[1]https://filecoin.io/blog/participate-in-our-trusted-setup-ceremony/ https://filecoin.io/blog/participate-in-our-trusted-setup-ce...
[2] https://eprint.iacr.org/2018/046.pdf https://eprint.iacr.org/2018/046.pdf
- hanniabu 6y agoIf I'm not mistaken, I believe they're found a way for a trustless setup a few months ago. Unfortunately I don't have any more info on hand, but I remember reading that in passing in regards to research performed by Ethereum developers.
- abecedarius 6y agoI'm not up on the math, but https://electriccoin.co/blog/halo-recursive-proof-composition-without-a-trusted-setup/ https://electriccoin.co/blog/halo-recursive-proof-compositio... sounded like that sort of thing.