<oembed><type>rich</type><version>1.0</version><author_name>npub1assqju94qjdpunps2yck2vtzfhnme5pclv0aantfajkjs5w2057quzu5p3</author_name><author_url>https://nostr.ae/npub1assqju94qjdpunps2yck2vtzfhnme5pclv0aantfajkjs5w2057quzu5p3</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-03-08&#xA;📝 Original message:On 8 March 2014 17:10, Alan Reiner &lt;etotheipi at gmail.com&gt; wrote:&#xA;&#xA;&#xA;&gt; I create a new keypair, &lt;c_pub&gt; with &lt;c_priv&gt; which I know (it can be any&#xA;&gt; arbitrary key pair).  But I don&#39;t give you &lt;c_pub&gt;, I give you  &lt;b_pub&gt; =&#xA;&gt; &lt;c_pub&gt; minus &lt;a_pub&gt; (which I can do because I&#39;ve seen &lt;a_pub&gt; before&#xA;&gt; doing this).&#xA;&gt;&#xA;&gt; Sure, I don&#39;t know the private key for &lt;b_pub&gt;, but it doesn&#39;t matter...&#xA;&gt; because what&#xA;&gt;&#xA;&gt; &lt;b_pub&gt; + &lt;a_pub&gt; = &lt;c_pub&gt; (mine)&#xA;&gt;&#xA;&gt; You have no way to detect this condition, because you don&#39;t know what&#xA;&gt; c_pub/c_priv I created, so you can only detect this after it&#39;s too late&#xA;&gt; (after I abuse the private key)&#xA;&gt;&#xA;&#xA;Thanks Alan and Forrest, that makes sense. So to salvage the situation in&#xA;the original case, we have to make sure the parties exchange their public&#xA;keys first, before they&#39;re allowed to see the public keys they&#39;ll be&#xA;combining them with.&#xA;&#xA;-- &#xA;-- &#xA;Edmund Edgar&#xA;Founder, Social Minds Inc (KK)&#xA;Twitter: @edmundedgar&#xA;Linked In: edmundedgar&#xA;Skype: edmundedgar&#xA;http://www.socialminds.jp&#xA;&#xA;Reality Keys&#xA;@realitykeys&#xA;ed at realitykeys.com&#xA;https://www.realitykeys.com&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20140308/ef8e3571/attachment.html&gt;</html></oembed>