Add CypherStack Carrot Spec Review
Carrot Peer Review
This CCS will provide funding for the first step towards a Carrot implementation in Monero. Carrot is a specification for a backwards-compatible addressing protocol, as well as a new wallet key hierarchy for the upcoming FCMP++ consensus upgrade. This peer review will be over the specification, not any specific implementation. CypherStack was chosen for this audit from among several firms during the Monero Resarch Lab meetings the last couple weeks.
Scope / Deliverables
A full peer review of the spec document [link]. Note that at the time of writing this proposal, the paper is not yet published in a peer-reviewed conference/journal.
The deliverable is a write-up which will include security proofs for all properties listed in section 9. It will also include notes on weaknesses, issues, or recommendations (if any). In the case that a security proof is not possible, a note will be included describing why that proof is not possible. In the case that CypherStack requires more funds to complete the security proofs, an MRL meeting will be held and a new CCS may be opened.
Out of scope
- Multiparty computation. There are no specific protocols presented for this, and no corresponding security model of proofs of security.
- Colloborative construction. For the same reason as multiparty computation.
Funding
Because CypherStack has had a long successful history with Monero, has agreed to accept the XMR directly, wishes to mitigate volatility risks, and has received upfront payment for reviews before, the 126 XMR for this review is to be paid out in full to Cypherstack immediately upon reaching the funding goal.
Merge request reports
Activity
mentioned in commit 738270f9
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Carrot Spec Peer Review Milestone Update Funding goal of 126 XMR has been reached as of 22 October 2024. Payout is requested immediately. The payout address obtained from Diego from Cypherstack over Matrix is: 87QkJp9a3ob6nv4RC5Uu7gExAQMxw6gUzB89SQ9jjiSx2FJU5d9QHqZUNGuwAP1awugm2gr9cEqMNDXV654v4MQyCBrJNXT Please cross-check this address against different sources. Deliverable will be made available after review work is completed. -----BEGIN PGP SIGNATURE----- iQHLBAEBCgA1FiEELqrJMOa5DLAZwB6Ab3l5em45JEIFAmcX7YQXHGplZmZybzI1 NkB0dXRhbm90YS5jb20ACgkQb3l5em45JEK72gv/ZE4nqPAL00dcH17dNeEu9g8M 39Bd5/HcUg4MDZvchxrc03APZir+x63KBnSh3rJrS8c9/YQ/OKbXgtxkycLiFQ85 mzrWEQHCdpkrFCM/lsBOnP++XHIKW+LWYrHc884TJbMbLe36auz5fAh4NvhHKK9J nOStF9/0YsajIq7/XF0yeKzLjZYF/ebDHkYOSlR34UDs1blTXW6TwkvjDfqLUPu/ 4mF9ZKXL3RnfBmFjaNaP9edqF+W6gjUyzboTXwzfmuOe+XZXS55pqyzdaxrFqz21 VepLQ5jq6yw7LBLZwmIQewt5BLettW6Qsa7CkFTjLlQo7rxhjl+LBRDXlNBbqnbX 9vilhvmc1zmz8rsLdniQAjdOozdsibTt/di7Rwe/bNfFH09r/6+wwn8yrqncT0Xg XTQE9uI2Fd+CblvnDV+OyKzkdcqdzPtEVszneG1H8EAdQEzxbAtL3UcWS+AMiy87 QvAso+d0SE6RcYH3YcXWmF862VXJ6ZROsaD+ohmi =4bNW -----END PGP SIGNATURE-----