To date, post-quantum Bitcoin discussions have largely centered on which digital signature schemes offer the strongest cryptographic security against a quantum adversary.
But cryptographic assumptions are only one dimension of security.
Different signature schemes introduce different implementation and operational risks. How should Bitcoin weigh cryptographic conservatism against the complexity required to deploy that cryptography safely?
While hash-based signatures are often favored for their conservative assumptions, CTO of Ledger, Charles Guillemet argues that evaluating primitives in isolation can obscure consequential risks at the systems level.
Stateful hash-based schemes, in particular, introduce state-management requirements where operational or user error can have catastrophic consequences —despite their conservative cryptographic foundations.
In this interview, Charles and I examine the tradeoffs of hash-based signatures and his case for greater consideration of lattice-based alternatives, i.e. ML-DSA.
A very juicy episode for anyone seriously assessing Bitcoin's post-quantum design landscape.
This episode of Bitcoin Rails is brought to you by:
LayerTwo Labs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301)
Hashi on Sui Network — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity
BitBox — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount