<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-04&#xA;📝 Original message:On Fri, Apr 4, 2014 at 6:51 AM, Nikita Schmidt&#xA;&lt;nikita at megiontechnologies.com&gt; wrote:&#xA;&gt; Fair enough.  Although I would have chosen the field order (p) simply&#xA;&gt; because that&#39;s how all arithmetic already works in bitcoin.  One field&#xA;&gt; for everybody.  It&#39;s also very close to 2^256, although still smaller&#xA;&gt; than your maximum prime.  Now of course with different bit lengths we&#xA;&gt; have to pick one consistency over others.&#xA;&#xA;Operation mod the group order is how secret keys must be combined in&#xA;type-2 private derivation for BIP-32. It&#39;s also absolutely essential&#xA;if you want to build a secret sharing scheme in which the shares are&#xA;usable for threshold ECDSA.&#xA;&#xA;I still repeat my concern that any private key secret sharing scheme&#xA;really ought to be compatible with threshold ECDSA, otherwise we&#39;re&#xA;just going to have another redundant specification.</html></oembed>