4 ms·
Bitcoin addresses are not public keys, they are the hash of the public key. Therefore you can not use a QC to derive the private key from the address alone (sin
by 6nf 5y ago
Bitcoin addresses are not public keys, they are the hash of the public key. Therefore you can not use a QC to derive the private key from the address alone (since the hash function is QC safe)
The public key is only written to the blockchain when you spend coin from that address, so at that point a QC can attack the key. Thus it's important to never re-use an address once you've spent from it and always spend the entire amount by using a newly generated change address.
- greyface- 5y ago> The public key is only written to the blockchain when you spend coin from that address As Canada points out[1], there is a window when it's revealed to the mempool but not yet committed to the blockchain. During that time, even a single-use address is not QC safe. [1]: https://news.ycombinator.com/item?id=27498750 https://news.ycombinator.com/item?id=27498750
- 6nf 5y agoYup that is correct but that window is reduced to a minimum. Your adversary will need to crack your PK in 10 mins and submit a replacement transaction which may or may not be accepted.
- tracedddd 5y agoIt’s possible to skip the mempool, by including it directly in a block, giving no time to a QC attacker. Not worth it right now, but if QC was known to exist it could be done.
- greyface- 5y agoIs there a way to guarantee that this block doesn't become orphaned? A transaction isn't truly committed to the blockchain until it has several confirmations.
- tracedddd 5y agoThere’s no way to guarantee absolutely, but you could wait to announce until you got lucky with a couple consecutive blocks if you had a lot of hashpower (pool operators). It would be an expensive endeavor since it involves throwing away solved blocks, but could of course package many QC safe(r) transactions so probably a profitable service in a QC compromised era.
- simonmales 5y agoDo you mean by mining the block yourself? Or a really high transaction fee?
- tracedddd 5y agoWell, not necessarily yourself, but through an entity that would not gossip the pending transaction. If it paid well any pool or mining farm could include it. A high standard transaction fee would not help.
- escalt 5y agoAlso worth noting that good bitcoin wallets automatically use a new address for every transaction, so you never end up reusing an address.
- haakon 5y agoIn the early days of Bitcoin, P2PK was used, where the public key is exposed instead of a hash of it. At least a million coins are covered by that. I would expect someone yielding a theoretical QC to attack those first.
- HWR_14 5y ago>Thus it's important to never re-use an address once you've spent from it and always spend the entire amount by using a newly generated change address. How does that work? Anytime you spend coins from an address you hope you spend the exact correct amount that was already there? You pay 2x transaction fees to have to transfers - payment as one and remainder as the other and hope they both pop in the same block?
- x4e 5y agoBitcoin transactions always spend 100% of your coins, however they can have multiple outputs. So to pay for something while still retaining the change, you can have one output going towards the merchant with the required amount and one output going straight back to your own wallet with the remaining coins. Only one fee is needed and everything is within one transaction. You can also send the change to a new address instead, which is how single use wallets work. You generate a new wallet, send the change to the new wallet and replace usage of the old wallet with the new one.
- HWR_14 5y agoIf you have one wallet with 17 addresses, doesn't this defeat the whole "your entire bitcoin cache can be protected by memorizing one 12 word phrase" aspect.
- x4e 5y agoSorry for the late response. Yes, there is certainly a trade off which must be made for the increased security. Another possible way would be to use a rotatable key derivation algorithm, where you can provide the 12 word phrase plus a number n, and it will provide you a different wallet for each value of n. Of course the key derivation algorithm must be quantam secure for the security benefit to apply in this context.