Does Silent Payments require the sender's input public key to be recoverable from the transaction?
Does Silent Payments require the sender's input public key to be recoverable from the transaction?
Loading saved threads...
Aaron Zhang · External communityPost link
External question — Bitcoin Stack Exchange
Author: Aaron Zhang
Original post: https://bitcoin.stackexchange.com/questions/130660
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
When I implemented a Silent Payments send on testnet, I used a Taproot key-path spend as input. In that case, the sender's public key is directly readable from the witness.
But I'm not sure this holds for all input types. For example, in a P2WPKH input the pubkey is in the witness, but for a Taproot script-path spend it may not be directly recoverable.
Does BIP352 require the sender's input pubkey to be recoverable? And if the sender uses an input type where the pubkey is not visible, does the protocol break down?
Quote
Report
Post Reply
Quoted from Forex.com.bd-Editorial External question — Bitcoin Stack Exchange Author: Aaron Zhang Source score (net votes, not local likes): 0 Original post: https://bitcoin.stackexchange.com/questions/130660 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. When I implemented a Silent Payments send on testnet, I used a Taproot key-path spend as input. In that case, the sender's public key is directly readable from the witness. But I'm not sure this holds for all input types. For example, in a P2WPKH input the pubkey is in the witness, but for a Taproot script-path spend it may not be directly recoverable. Does BIP352 require the sender's input pubkey to be recoverable? And if the sender uses an input type where the pubkey is not visible, does the protocol break down?
Checking account access…