<oembed><type>rich</type><version>1.0</version><author_name>npub1cmt6gqyfw3sdngkq0wadtpe3kmgyyeld6ad0g2h5tar3kpzcrmpqddwkls</author_name><author_url>https://nostr.ae/npub1cmt6gqyfw3sdngkq0wadtpe3kmgyyeld6ad0g2h5tar3kpzcrmpqddwkls</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2018-07-08&#xA;📝 Original message:Hi Erik,&#xA;&#xA;On Sun, 2018-07-08 at 10:19 -0400, Erik Aronesty via bitcoin-dev wrote:&#xA;&gt; Consider changing the &#34;e&#34; term in the schnorr algorithm to hash of&#xA;&gt; message (elligator style) to the power of r, rather than using&#xA;&gt; concatenation.  &#xA;&#xA;How do you compute s = x*e if e is an element of group G?&#xA;(Similar question: How do you verify if e is element of G?)&#xA;&#xA;Are you aware of &#xA; http://cacr.uwaterloo.ca/techreports/2001/corr2001-13.ps ?&#xA;This is a threshold signature scheme for Schnorr signatures, so what&#xA;you want is possible already with Schnorr signatures.&#xA;&#xA;Best,&#xA;Tim</html></oembed>