{"type":"rich","version":"1.0","author_name":"npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","author_url":"https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2018-09-05\n📝 Original message:Correct, there is an interaction step to deduce G*k, when signing, each\nparticipant has to publishes G*ki. I didn't talk about it.   That doesn't\nbreak it, but you're correct, it's not non-interactive.\n\nOn Wed, Sep 5, 2018 at 9:06 AM Andrew Poelstra \u003capoelstra at wpsoftware.net\u003e\nwrote:\n\n\u003e On Wed, Sep 05, 2018 at 08:26:14AM -0400, Erik Aronesty wrote:\n\u003e \u003e Why would you call it FUD?   All the weird hemming and hawing about it is\n\u003e \u003e really strange to me.  The more I look into it and speak to professors\n\u003e \u003e about i, the more it seems \"so trivial nobody really talks about it\".\n\u003e \u003e\n\u003e \u003e 1. Generate an M of N shared public key (done in advance of signing ....\n\u003e \u003e this gets you the bitcoin address)\n\u003e \u003e 2. Generate signature fragments (this can be done offline, with no\n\u003e \u003e communication between participants)\n\u003e \u003e\n\u003e \u003e Detailed explanation with code snippets:\n\u003e \u003e\n\u003e \u003e\n\u003e https://medium.com/@simulx/an-m-of-n-bitcoin-multisig-scheme-e7860ab34e7f\n\u003e \u003e\n\u003e\n\u003e The hemming and hawing is because you've been repeatedly told that your\n\u003e scheme doesn't work, and to please implement it in some computer algebra\n\u003e system so that you can see that (or so we can see where your mistake is),\n\u003e and you instead continue to post incomplete/incoherent copies of the same\n\u003e thing across multiple mediums - Reddit, this list, Bitcointalk, Medium,\n\u003e etc ad nauseum.\n\u003e\n\u003e It's distracting and offensive to people who have spent a lot of time and\n\u003e energy thinking about this stuff, and more importantly it causes confusion\n\u003e in the public eye. Phrasings like \"weird hemming and hawing\" suggest that\n\u003e we don't know/don't care about some insight you have, which is not true.\n\u003e This is why your posts are FUD.\n\u003e\n\u003e For example, in your linked post I looked at every single instance of the\n\u003e character 'k' and *not one of them* defined the value 'k' from which 'R'\n\u003e is derived in the signing procedure.\n\u003e\n\u003e\n\u003e Of course there is no possible value, individual signers cannot learn 'R'\n\u003e at signing time without interaction, and your whole scheme is broken. Given\n\u003e the number of times you've been told this, I find it hard to believe that\n\u003e this was an honest mistake.\n\u003e\n\u003e\n\u003e\n\u003e Andrew\n\u003e\n\u003e\n\u003e\n\u003e --\n\u003e Andrew Poelstra\n\u003e Research Director, Mathematics Department, Blockstream\n\u003e Email: apoelstra at wpsoftware.net\n\u003e Web:   https://www.wpsoftware.net/andrew\n\u003e\n\u003e \"Make it stop, my love; we were wrong to try\n\u003e  Never saw what we could unravel in traveling light\n\u003e  Nor how the trip debrides like a stack of slides\n\u003e  All we saw was that time is taller than space is wide\"\n\u003e        --Joanna Newsom\n\u003e\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180905/c737fbbf/attachment-0001.html\u003e"}
