Why Nostr? What is Njump?
2025-03-26 11:33:13
in reply to

waxwing on Nostr: Yes, right. I get where you're coming from. I agree that linkability is a ...

Yes, right. I get where you're coming from. I agree that linkability is a nice-to-have feature here, maybe not essential. For spontaneity, yes, you get that with the AOS style (all of its derivatives, LWW, LSAG etc), I guess in practice it only ever mattered in cryptocurrency; because the nice idea of spontaneous ring formation rarely ended up being useful in practice; people have to have a key that you can spontaneously choose; if the number of such people is small enough, why not choose them all? IIRC Liu Wei Wong actually covered this point in one interesting way, suggesting that you could spontaneously form ring sigs over keys of different types (e.g. RSA and ECDSA etc.).

From a 20 minute look through the results for "ring signature" on github, I agree with you that it's hard to impossible to find an existing library that is reputable enough/well enough developed to be usable for a generic ring signature application of the type you're looking for. It's, I guess, a function of the fact that ring signatures never reached the threshold of common usage that led to them being included into the big crypto toolkits like you find in popular languages like Python and Javascript etc. After all they were never standardized by NIST and I don't think an RFC exists.
Author Public Key
npub1vadcfln4ugt2h9ruwsuwu5vu5am4xaka7pw6m7axy79aqyhp6u5q9knuu7