3 ms·
Signing and hashing are specific cryptographic operations with well defined properties. You can’t use them interchangeably if you want to be taken seriously.
by abiro 5y ago
Signing and hashing are specific cryptographic operations with well defined properties. You can’t use them interchangeably if you want to be taken seriously.
- falcolas 5y agoA merkle tree that uses cryptographic signing instead of hashing is still a merkle tree. Though if we really feel it's necessary, we could simply say "a merkle-tree like implementation that uses cryptographic signatures in place of a hash function". Pedantry about the difference between hashes and signatures doesn't change the validity of the structure as a response to the original question.
- abiro 5y agoI challenge you to build a Merkle tree using a digital signature scheme in place of a cryptographic hash function where a Merkle tree constructed by Alice can be used by Bob without revealing Alice’s secret key.
- falcolas 5y agoOK. Challenge accepted. Alice and Bob both use asymmetric keys, and use one of a thousand different methods to exchange their public keys (hey, they can even go in the Merkle tree). Alice signs a transaction using her private key and publishes it. Bob can now use Alice's public key to verify the signature on the transaction. No private/secret key exposure. Asymmetric encryption is a fairly well explored field, which is what makes the above both easy to reason about and secure.
- abiro 5y agoOk well played, you’ve trolled me masterfully.