Giving teeth to expected EC disabling: P2XX(-T)(-ML)

Posted by waxwing/ AdamISZ

Aug 15, 2026/14:49 UTC

The discussion on the Bitcoin Development Mailing List raised significant concerns regarding the use of 192-bit versus 256-bit ECC in the context of potential quantum computing threats. The key point of contention is the timing and practicality of upgrading from 192-bit to 256-bit ECC, given the uncertain pace at which quantum computing might advance to compromise these cryptographic standards. The argument is made that while 192-bit ECC could be susceptible earlier than 256-bit, the latter does not necessarily extend the secure period significantly enough to justify the complexity of transitioning.

Additionally, there's a debate about the likelihood of general misunderstanding should a 192-bit canary (a warning system) be broken by quantum computing capabilities. It was argued that such an event would likely generate a substantial and justified alarm rather than being dismissed as a false positive. This perspective emphasizes the need for clear communication and understanding within the community regarding the implications of quantum advancements on existing cryptographic protections.

Another technical aspect discussed involves the method of generating cryptographic challenges, particularly using hash functions like SHA2 in conjunction with ECC. The conversation points out that if SHA2 behaves as a proper random oracle, its use in encoding generators (G) could mirror the Elliptic Curve Discrete Logarithm Problem (ECDLP) closely, which is desirable for security frameworks. However, nuances exist, such as whether SHA2 possesses any inherent structure that might align with or differ from secp256k1, affecting its efficacy in this role.

The email also critiques the use of BIP341's hashing approach in a post-quantum scenario where a Shor's algorithm could potentially compromise ECC-based systems directly. An alternative suggestion was to double-hash the encoded generator using SHA2 to enhance security against quantum attacks, thus preventing direct theft of coins through cryptographic breaches enabled by quantum computing.

This discussion underscores the complex balance between advancing cryptographic methods to counter quantum computing threats and the practical challenges associated with such advancements, including community perception and technological implementation.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback