<oembed><type>rich</type><version>1.0</version><author_name>npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_name><author_url>https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2018-09-05&#xA;📝 Original message:Correct, there is an interaction step to deduce G*k, when signing, each&#xA;participant has to publishes G*ki. I didn&#39;t talk about it.   That doesn&#39;t&#xA;break it, but you&#39;re correct, it&#39;s not non-interactive.&#xA;&#xA;On Wed, Sep 5, 2018 at 9:06 AM Andrew Poelstra &lt;apoelstra at wpsoftware.net&gt;&#xA;wrote:&#xA;&#xA;&gt; On Wed, Sep 05, 2018 at 08:26:14AM -0400, Erik Aronesty wrote:&#xA;&gt; &gt; Why would you call it FUD?   All the weird hemming and hawing about it is&#xA;&gt; &gt; really strange to me.  The more I look into it and speak to professors&#xA;&gt; &gt; about i, the more it seems &#34;so trivial nobody really talks about it&#34;.&#xA;&gt; &gt;&#xA;&gt; &gt; 1. Generate an M of N shared public key (done in advance of signing ....&#xA;&gt; &gt; this gets you the bitcoin address)&#xA;&gt; &gt; 2. Generate signature fragments (this can be done offline, with no&#xA;&gt; &gt; communication between participants)&#xA;&gt; &gt;&#xA;&gt; &gt; Detailed explanation with code snippets:&#xA;&gt; &gt;&#xA;&gt; &gt;&#xA;&gt; https://medium.com/@simulx/an-m-of-n-bitcoin-multisig-scheme-e7860ab34e7f&#xA;&gt; &gt;&#xA;&gt;&#xA;&gt; The hemming and hawing is because you&#39;ve been repeatedly told that your&#xA;&gt; scheme doesn&#39;t work, and to please implement it in some computer algebra&#xA;&gt; system so that you can see that (or so we can see where your mistake is),&#xA;&gt; and you instead continue to post incomplete/incoherent copies of the same&#xA;&gt; thing across multiple mediums - Reddit, this list, Bitcointalk, Medium,&#xA;&gt; etc ad nauseum.&#xA;&gt;&#xA;&gt; It&#39;s distracting and offensive to people who have spent a lot of time and&#xA;&gt; energy thinking about this stuff, and more importantly it causes confusion&#xA;&gt; in the public eye. Phrasings like &#34;weird hemming and hawing&#34; suggest that&#xA;&gt; we don&#39;t know/don&#39;t care about some insight you have, which is not true.&#xA;&gt; This is why your posts are FUD.&#xA;&gt;&#xA;&gt; For example, in your linked post I looked at every single instance of the&#xA;&gt; character &#39;k&#39; and *not one of them* defined the value &#39;k&#39; from which &#39;R&#39;&#xA;&gt; is derived in the signing procedure.&#xA;&gt;&#xA;&gt;&#xA;&gt; Of course there is no possible value, individual signers cannot learn &#39;R&#39;&#xA;&gt; at signing time without interaction, and your whole scheme is broken. Given&#xA;&gt; the number of times you&#39;ve been told this, I find it hard to believe that&#xA;&gt; this was an honest mistake.&#xA;&gt;&#xA;&gt;&#xA;&gt;&#xA;&gt; Andrew&#xA;&gt;&#xA;&gt;&#xA;&gt;&#xA;&gt; --&#xA;&gt; Andrew Poelstra&#xA;&gt; Research Director, Mathematics Department, Blockstream&#xA;&gt; Email: apoelstra at wpsoftware.net&#xA;&gt; Web:   https://www.wpsoftware.net/andrew&#xA;&gt;&#xA;&gt; &#34;Make it stop, my love; we were wrong to try&#xA;&gt;  Never saw what we could unravel in traveling light&#xA;&gt;  Nor how the trip debrides like a stack of slides&#xA;&gt;  All we saw was that time is taller than space is wide&#34;&#xA;&gt;        --Joanna Newsom&#xA;&gt;&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180905/c737fbbf/attachment-0001.html&gt;</html></oembed>