{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2014-04-04\n📝 Original message:On Fri, Apr 4, 2014 at 6:51 AM, Nikita Schmidt\n\u003cnikita at megiontechnologies.com\u003e wrote:\n\u003e Fair enough.  Although I would have chosen the field order (p) simply\n\u003e because that's how all arithmetic already works in bitcoin.  One field\n\u003e for everybody.  It's also very close to 2^256, although still smaller\n\u003e than your maximum prime.  Now of course with different bit lengths we\n\u003e have to pick one consistency over others.\n\nOperation mod the group order is how secret keys must be combined in\ntype-2 private derivation for BIP-32. It's also absolutely essential\nif you want to build a secret sharing scheme in which the shares are\nusable for threshold ECDSA.\n\nI still repeat my concern that any private key secret sharing scheme\nreally ought to be compatible with threshold ECDSA, otherwise we're\njust going to have another redundant specification."}
