注册并分享邀请链接,可获得视频播放与邀请奖励。

与「STARK」相关的搜索结果

STARK 贴吧
一个关键词就是一个贴吧,路径全站唯一。
创建贴吧
用户
未找到
包含 STARK 的内容
A note on recursive STARK mempools (EIP-8288) This is an EIP that I am hoping we can get included in I-star (the fork after Hegota) that you can think of as the next step after Frames, that would unlock extreme amounts of power. Particularly: * Ultra-cheap quantum-safe signatures (SPHINCS-). Much of the cost savings comes from the fact that the signature data (~3 kB) does not have to go onchain * Ultra-cheap quantum-safe privacy protocols. Status quo minimum cost for private txs is ~300k if you engineer very well (no one does), status quo quantum-safe is ~10M gas, this could reduce it to low tens of thousands. * Universal support for your favorite new signature or proof scheme without needing EVM changes. Whatever you use (Falcon, ML-DSA, some other lattice-based thing, something code-based or isogeny-based or even more esoteric), you can just wrap it client-side in a STARK, onchain gas cost low tens of thousands just like privacy protocols. Hopefully, Ethereum will never need "please support my favorite cryptographic algo" politics again. * Private account abstraction: keep your account logic private, and in a private location onchain. Then you can make one transaction to change the ownership of all your onchain state - accounts, defi positions, privacy protocol notes, everything - without revealing which objects' ownership you're changing. Here's how it works. Your transaction can include a type of frame that we call a "dependency frame". The frame is a list of statements, asserting claims like "message hash M was signed by SPHINCS- public key P" and "data hash D was proven to satisfy a statement defined by verification key V". When you send your transaction, you send it in an envelope, which includes a signature or a STARK for each statement in a dependency frame. Once the transaction reaches the mempool, nodes aggregate them. Each node runs a loop: wait one tick (eg. 500ms), aggregate all new envelopes (either single-tx or multi-tx) that you've seen, remove any transactions that are expired, generate a STARK recursively proving all dependencies, and send a new multi-tx envelope containing that STARK. Hence, the bandwidth load is bounded: each node's outbound is one STARK (~100-300 kB) per tick, plus each transaction getting broadcasted through the network once (as happens already). The block builder acts as "yet another mempool node", receiving envelopes from the mempool (plus any side channels), generates its own STARK covering the subset of transactions it intends to include in the block, and adds that STARK to the block. Total onchain overhead: one STARK (100-300 kB), plus 96 bytes for each statement being proven. This is what I've called before ( ) "The Proof Singularity". Today, we have all the ingredients to actually implement it. As a developer, this requires a somewhat different workflow than you are used to, but it is conceptually simple. Any signatures or STARKs, you put into a separate frame. Then the main logic that today is verifying a signature or STARK, you replace with checking for the existence of a frame that includes the correct statement as a dependency. Examples of useful statements: * [tx sighash] verifies against [the pubkey at sload(0)] * there exists a secret and a merkle branch such that hashing secret+0 and applying the merkle branch outputs (public) root R, and hashing secret+1 outputs (public) nullifier N * there exists a secret address A, salt S and signature Z such that sload(0) = hash(A, S) and a merkle proof of address A inside a recent ethereum state contains some pubkey D where [tx sighash] was signed by D [this is private account abstraction; all variables except [tx sighash] and sload(0) are private; you can also make D a STARK verification key] * there exists an ML-DSA signature signing [tx sighash], that verifies against an ML-DSA pubkey whose hash is sload(0) At the core, this is moving any compute and data other than bookkeeping "business logic" outside the core path of Ethereum execution, sharding and parallelizing it via the mempool. Notice also that this requires agreeing on a _language_ (aka. an ISA) for the recursive STARKs to define statements in. The current leading candidate is RISC-V. So this would also de-facto be Ethereum adding RISC-V (or something else we decide on) as a canonical ISA - a big decision that should be done carefully, but that I think will be necessary to drive Ethereum forward.
显示更多
昨天,全球首笔抗量子比特币交易在香港亮相。 8月27日香港比特币峰会上,Starknet 基金会展示了一笔刚被矿工写入比特币主网的特殊交易。 未来即使量子计算机算出私钥,也无法直接把这笔币转走。 这套方案名为QSB,由区块链密码学公司StarkWare开发,StarkWare 也是Starknet的原始开发团队。 普通比特币转账发出后,公钥会公开,足够强的量子计算机可能根据公钥算出私钥,再伪造一笔转账。 QSB 给这笔币增加了第二道锁。 它依靠哈希函数保护,即使私钥被算出来,攻击者仍然缺少打开第二道锁的信息。 这笔交易沿用了现有的比特币规则,没有软分叉,也没有升级协议,现在只有主动转入QSB结构的币能获得保护,其他地址不会自动发生变化。 QSB 目前还不能通过普通节点传播,需要直接交给矿工处理,生成一笔交易也要消耗大量链下算力,成本达到数百美元。 普通钱包尚未支持这种交易,私钥遗失的旧币也无法主动迁移。
显示更多
LATEST: ⚡ StarkWare completed a quantum-resistant Bitcoin transaction on mainnet using Avihu Levy’s QSB method, showing it can work under existing rules but requiring up to $200 in off-chain computing.
显示更多
0
29
56
8
转发到社区
StarkWare 研究人员 Avihu Levy 提出的 Quantum-Safe Bitcoin(QSB)方案已首次在 Bitcoin 主网上完成交易确认。该方案无需软分叉或修改现有共识规则,而是通过基于哈希函数的额外锁定机制,将交易安全性从椭圆曲线密码学转向哈希抗碰撞与抗原像能力,以降低未来 Shor 算法破解公钥密码体系带来的风险。QSB 目前仍属实验性方案,单笔离线计算成本约数百美元,且交易格式并非标准格式,需要通过 MARA Slipstream 等渠道直接提交给矿工。
显示更多
The Privacy Frontier: ZK meets TEE Most privacy panels explain why privacy matters, this one is two builders comparing the opposite bets they made. With @MayaDotan_ (StarkWare) and @AlexAuroraDev (NEAR), moderated by @jessiexiao_eth. Tomorrow, 1:00 PM GMT. Hosted on @Starknet.
显示更多
0
10
81
12
转发到社区
可以把尼采的“权力意志”(Wille zur Macht)理解成一句话: 生命不是单纯为了保存自己,而有一种不断扩张力量、克服阻力、超越自身、创造价值的冲动。 但有一个非常重要的文本学提醒:《权力意志》(The Will to Power)不是尼采生前完成并出版的一部著作,而是他精神崩溃以后,由遗稿笔记编辑而成,早期版本又受到其妹妹伊丽莎白等人的编排。因此研究尼采时,最好把“权力意志”放回《查拉图斯特拉如是说》《善恶的彼岸》《道德谱系》等正式著作及其遗稿中理解。 一、权力意志首先不是“争权夺利” 这是最容易误解尼采的地方。 尼采所谓 Macht,当然包含支配、竞争和力量,但远远不限于政治权力。一个艺术家创造作品、哲学家建立思想体系、运动员不断突破极限、一个人战胜自己的恐惧和软弱,在尼采意义上都可以表现为权力意志。 所以它更接近: 生命 → 释放力量 → 克服阻力 → 自我超越 → 创造新的价值。 因此尼采特别反对把人的最高目标理解成“幸福”“舒服”或者仅仅“生存”。 《反基督者》中有一句极具代表性的话: “什么是好的?——一切提高人的权力感、权力意志和权力本身的东西。” 紧接着又问: “什么是坏的?——一切源于软弱的东西。” 这是尼采最激烈的一面。 二、真正高级的权力,是征服自己 如果把尼采仅仅理解成“强者统治弱者”,其实把他读浅了。 《查拉图斯特拉如是说》贯穿着一个更重要的概念: Selbstüberwindung——自我克服、自我超越。 人最大的敌人未必是别人,而是昨天的自己。 因此“超人”(Übermensch)也不应该简单理解成政治强人。它首先意味着一种不断创造自己的生命形态: 你不是寻找一个现成的“我”,而是在创造一个“我”。 这和尼采非常著名的一句话相连: “成为你自己。” Werde, der du bist. 看起来矛盾——既然已经是自己,为什么还要成为自己? 因为尼采认为现实中的你只是材料,真正的你还需要通过选择、痛苦、创造和自我克服塑造出来。 三、“上帝死了”以后,谁来创造价值? 这可能是理解权力意志最重要的入口。 尼采的名句: “上帝死了!上帝仍然死着!是我们杀死了他。” 并不是简单宣布“没有上帝”。 他真正担忧的是:欧洲现代性、科学和理性已经瓦解传统基督教世界观,但欧洲人的道德价值仍然建立在原来的宗教基础上。 如果最高价值的根基消失,人为什么还要相信原来的善恶? 这就是尼采所说的虚无主义危机。 所以权力意志最终进入价值哲学: 旧价值崩溃之后,人不能永远靠别人告诉自己什么是真理、什么是善。 强健的生命必须拥有创造价值的能力。 这就是尼采所谓: “一切价值的重估”(Umwertung aller Werte)。 四、主人道德与奴隶道德 《道德谱系》里,尼采进一步追问: 我们为什么把某些东西叫作“善”? 他认为道德不是从天上掉下来的,也不是天然存在的。不同的生命状态会创造不同的价值体系。 “主人道德”从自身力量出发: 勇敢、卓越、尊严、创造、独立 → 好。 而“奴隶道德”则可能从怨恨(Ressentiment)出发,把强者的力量重新定义成邪恶: 你强大,所以你恶;我弱小,所以我善。 尼采并不是简单鼓励欺负弱者,而是在进行一种非常激进的道德谱系学:当有人宣称“这是正义”“这是道德”时,不仅要问他说得对不对,还要追问: 是谁定义的?为什么这样定义?这种价值判断背后有什么心理与权力结构? 这对后来福柯等人的思想影响非常大。 五、尼采几句最值得记住的话 有些中文流传版本翻译差异很大,我给你意思最可靠的常见译法: “凡不能杀死我的,使我更强大。” Was mich nicht umbringt, macht mich stärker. ——《偶像的黄昏》 “没有事实,只有解释。” Es gibt keine Tatsachen, nur Interpretationen. ——尼采遗稿 (这句尤其要注意,它不是尼采正式出版著作中的格言。) 还有一句与你最近思考“道统、价值、权力合法性”的问题特别接近: “谁不能服从自己,就会被别人命令。” ——《查拉图斯特拉如是说》 以及: “人是应当被超越的东西。” 这其实比“权力意志”四个字更能代表尼采。 如果把尼采压缩成一个思想结构 我会这样概括: 上帝之死 → 传统最高价值失去绝对基础 → 虚无主义出现 → 人必须重新评价价值 → 权力意志成为生命创造与自我超越的动力 → 超人代表能够承担价值创造责任的人。 所以尼采最深刻的地方,并不是教人怎样获得权力。 而是提出一个现代文明至今没有彻底解决的问题: 当传统的神圣秩序失去约束力之后,人靠什么约束自己?谁有资格规定善恶?如果价值最终由人创造,那么创造价值的人又受什么约束? 这恰好可以与你刚才关于哥贝克力石阵的思考形成一个非常有意思的首尾呼应:文明之初,人类通过神圣力量建立高于自己的秩序;到了尼采这里,现代人宣布“上帝死了”,那个超越性秩序发生危机。于是现代性最危险的问题出现了——当人自己成为价值的创造者以后,权力会不会最终把自己也宣布为真理? 这其实已经可以直接进入你所关心的“道统—法统—权力”问题了。以上为AI认知的尼采
显示更多
Marvel Studios has announced 'IRON MAN: REBUILT', set to release on May 5, 2028. Timothée Chalamet is set to play the new Tony Stark. #D23#
0
3K
100.8K
7K
转发到社区
🔓 Top Token Unlocks This Week (Aug 10 - Aug 16) 1️⃣ Rain (RAIN) - $506.9M; 5.64% circ supply 2️⃣ Pump​.​fun (PUMP) - $20.0M; 1.80% circ supply 3️⃣ Pieverse (PIEVERSE) - $15.4M; 7.30% circ supply 4️⃣ Avalanche (AVAX) - $10.9M; 0.39% circ supply 5️⃣ Arbitrum (ARB) - $7.4M; 1.40% circ supply 6️⃣ Aptos (APT) - $6.9M; 1.37% circ supply 7️⃣ Sei (SEI) - $5.1M; 1.65% circ supply 8️⃣ Starknet (STRK) - $4.0M; 2.39% circ supply 9️⃣ Official Trump (TRUMP) - $1.4M; 0.36% circ supply 🔟 Worldcoin (WLD) - $1.1M; 0.09% circ supply
显示更多
0
32
163
23
转发到社区
I updated my 2023 roadmap diagram to overlay where the items that were there sit in the current Strawmap ( ). In general, a lot of overlap, but: * Some things got reshuffled in order (eg. quantum safety up-prioritized) * Some things deprioritized (eg. VDFs; many EVM improvements) * Some things replaced with superior constructions (eg. Verkle -> unified BT -> PBT; state expiry -> new state types) What's most striking, however, is that some completely new things are in the strawmap that are NOT in this diagram, because they were not in the 2023 roadmap at all. These reflect changing priorities. Notably: * First-class attention to strong privacy. This covers: keyed nonces and recent roots, aspects of FOCIL, lean privacy pool & wormholes * Aggressive scaling in the context of post-quantum. This covers: leanSPHINCS signatures and aggregation, zkzk frames (see ) * Lean-ification of the spec, to assist in formal verification (full FV of everything is only possible because of modern AI) * Blob and gas futures (this idea just didn't exist back in 2023) * Native rollups (SNARKs were nowhere near mature enough to even consider this back in 2023) * A more open design space for the "future of the EVM". zkzk frames already implies that the protocol will expose to users some ISA that's not the EVM - current leading candidates are leanISA and RISC-V. These ISAs are more simple, modern and efficient than the EVM. Once they're there, why not expose them to developers everywhere? (And then, why not turn the EVM into being an IR on top of that ISA, instead of an enshrined feature massively complicating the base protocol?) Though much of the deeper exploration here is too early even for the strawmap. * New state types are not just a replacement for expiry, they're a fundamentally different paradigm to how Ethereum does scaling A common theme in scaling, found in both state types and zkzk frames (both new ideas), is that instead of trying to maximally scale ALL ethereum activity, we try to create specialized mechanisms that have more restrictive properties that make them more scaling-friendly, while supporting the heaviest loads incurred by users and applications today (eg. token transfers, swaps) and tomorrow (eg. privacy protocols). The other common theme is treating STARKs and AI-accelerated FV as first-class objects, that we are okay betting the technical future of Ethereum on. There are recursive STARKs in many layers of the protocol, one particular primitive (the "aggregate to union verified dependencies" primitive) is expected to be used in *three* places in the protocol: EL, CL and DL. This can only be safe with formal verification, which is itself only feasible with modern AI tools. In general, many steps forward in maturity. And a huge amount of hard work by many dozens of Ethereum researchers and developers on all of these features. Ethereum will be quantum-safe. Ethereum will put users' privacy first. Ethereum will be secure. Ethereum will be censorship-resistant. Ethereum will be highly performant and scalable while satisfying the above. And Ethereum will be Lean.
显示更多
0
279
1.7K
334
转发到社区
“We got the best fans in the world.” @starks_malaki
0
7
893
46
转发到社区