{"type":"rich","version":"1.0","author_name":"npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","author_url":"https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2018-09-11\n📝 Original message:- Musig, by being M of M, is inherently prone to loss.\n\n- Having the senders of the G*x pubkey shares sign their messages with the\nassociated private key share should be sufficient to prevent them from\nusing wagner's algorithm to attack the combined key.   Likewise, the G*k\nnonce fragments should also be signed with the pubkey shares.\n\n\n\nOn Tue, Sep 11, 2018 at 1:27 PM Gregory Maxwell \u003cgreg at xiph.org\u003e wrote:\n\n\u003e On Tue, Sep 11, 2018 at 5:20 PM Erik Aronesty \u003cerik at q32.com\u003e wrote:\n\u003e \u003e The security advantages of a redistributable threshold system are huge.\n\u003e  If a system isn't redistributable, then a single lost or compromised key\n\u003e results in lost coins... meaning the system is essetntially unusable.\n\u003e \u003e\n\u003e \u003e I'm actually worried that Bitcoin releases a multisig that encourages\n\u003e loss.\n\u003e\n\u003e There is no \"non- edistributiable multisig\" proposed for Bitcoin\n\u003e anywhere that I am aware of.\n\u003e\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180911/d39149db/attachment.html\u003e"}
