PQC output type discussion

Posted by sipa

Sep 17, 2026/03:19 UTC

The discussion revolves around the challenges and intricacies of implementing secure cryptocurrency protocols, particularly focusing on P2TRv2 and its comparison with potential new standards like P2MR. While P2TRv2 is easier to use correctly, its security isn't guaranteed even when used as intended. In contrast, P2MR offers enhanced security through more challenging usage requirements that could lead to better protection, albeit at the cost of usability. Address reuse continues to be a significant problem in cryptocurrency security. Despite attempts to shift away from this practice through innovations like the BIP70 payment protocol, such efforts have not gained widespread adoption. The ingrained habit of address reuse among users poses persistent security risks, underscoring the need for a different approach or layer, perhaps similar to Lightning Network's solutions which eliminate the reliance on address compatibility.

Furthermore, typical wallet practices like avoiding address reuse and keeping xpubs private can enhance security but require significant changes in user behavior and software design. These are not strictly software issues but involve broader workflow and social changes. For instance, hardware wallets and multi-signature setups, though more complex, represent crucial use cases that cater to a significant user base concerned with high-security standards. The introduction of CISA is seen as a compromise, potentially accepting some level of insecurity for better performance against classical threats, betting that quantum computing threats may not materialize imminently.

The debate extends into the feasibility of transitioning to post-quantum cryptography (PQC). This transition faces resistance due to increased costs and the inertia of existing user habits and wallet designs. Suggestions include simplifying the migration to PQC by removing economic disincentives such as fee increases, and rethinking key derivation methods to ensure security without overly complicating recovery processes. The idea of using ephemeral, randomly generated PQ keys was dismissed in favor of deterministic derivation directly linked to a user’s seed phrase, possibly bypassing traditional steps like BIP32.

Lastly, there's an acknowledgment of the formidable challenge in changing how people interact with technology, particularly in the context of security standards that may become obsolete in the future due to advancements in quantum computing. This underscores a broader dilemma in designing technologies that must balance between advancing security and accommodating user behaviors and expectations.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback