{"type":"rich","version":"1.0","author_name":"npub1cmt6gqyfw3sdngkq0wadtpe3kmgyyeld6ad0g2h5tar3kpzcrmpqddwkls","author_url":"https://nostr.ae/npub1cmt6gqyfw3sdngkq0wadtpe3kmgyyeld6ad0g2h5tar3kpzcrmpqddwkls","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2018-07-08\n📝 Original message:Hi Erik,\n\nOn Sun, 2018-07-08 at 10:19 -0400, Erik Aronesty via bitcoin-dev wrote:\n\u003e Consider changing the \"e\" term in the schnorr algorithm to hash of\n\u003e message (elligator style) to the power of r, rather than using\n\u003e concatenation.  \n\nHow do you compute s = x*e if e is an element of group G?\n(Similar question: How do you verify if e is element of G?)\n\nAre you aware of \n http://cacr.uwaterloo.ca/techreports/2001/corr2001-13.ps ?\nThis is a threshold signature scheme for Schnorr signatures, so what\nyou want is possible already with Schnorr signatures.\n\nBest,\nTim"}
