BITCOIN RAILS #
70#: THE CASE FOR LATTICE-BASED SIGNATURES IN BITCOIN | with CTO of
@Ledger Charles Guillemet
๐ YouTube:
๐ฟ Spotify:
To date, post-quantum Bitcoin discussions have largely centered on which digital signature schemes offer the strongest cryptographic security against a quantum adversary.
But cryptographic assumptions are only one dimension of security.
Different signature schemes introduce different implementation and operational risks. How should Bitcoin weigh cryptographic conservatism against the complexity required to deploy that cryptography safely?
While hash-based signatures are often favored for their conservative assumptions, CTO of Ledger, Charles Guillemet
@P3b7_ argues that evaluating primitives in isolation can obscure consequential risks at the systems level.
Stateful hash-based schemes, in particular, introduce state-management requirements where operational or user error can have catastrophic consequences โdespite their conservative cryptographic foundations.
In this interview, Charles and I examine the tradeoffs of hash-based signatures and his case for greater consideration of lattice-based alternatives, i.e. ML-DSA.
A very juicy episode for anyone seriously assessing Bitcoin's post-quantum design landscape.
This episode of Bitcoin Rails is brought to you by:
LayerTwo Labs
@LayerTwoLabs โ developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on
@SuiNetwork โ a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity
BitBox
@BitBoxSwiss โ an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount
TIMESTAMPS:
00:00 โ Intro
01:45 โ How the quantum threat became real for Ledger
09:06 โ NIST influence and what Ledger built into its SDK
21:25 โ ML-DSA and why Falcon might not be the right choice
25:33 โ The problem with hash-based signatures
31:38 โ Stateful signatures and the throughput problem
36:48 โ Does user error outweigh the security difference?
42:27 โ Bitcoin post-quantum migration scenario
45:15 โ Maintaining multisig capabilities in a post-quantum world
55:54 โ NIST standardization process and the backdoor question
1:01:06 โ Trezor's approach and device authentication
1:06:09 โ Ledgerโs approach to post-quantum signatures