<oembed><type>rich</type><version>1.0</version><author_name>npub1zw7cc8z78v6s3grujfvcv3ckpvg6kr0w7nz9yzvwyglyg0qu5sjsqhkhpx</author_name><author_url>https://nostr.ae/npub1zw7cc8z78v6s3grujfvcv3ckpvg6kr0w7nz9yzvwyglyg0qu5sjsqhkhpx</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2020-03-10&#xA;📝 Original message:&#xA;ZmnSCPxj &lt;ZmnSCPxj at protonmail.com&gt; writes:&#xA;&gt; Good morning Rusty, et al.,&#xA;&gt;&#xA;&gt;&#xA;&gt;&gt; Note that this means no payment secret is necessary, since the incoming&#xA;&gt;&gt; `blinding` serves the same purpose. If we wanted to, we could (ab)use&#xA;&gt;&gt; payment_secret as the first 32-bytes to put in Carol&#39;s enc1 (i.e. it&#39;s&#xA;&gt;&gt; the ECDH for Carol to decrypt enc1).&#xA;&gt;&#xA;&gt; I confess to not reading everything in detail, but it seems to me that, with payment point + scalar and path decorrelation, we need to establish a secret with each hop anyway (the blinding scalar for path decorrelation), so if you need a secret per hop, possibly this could be reused as well?&#xA;&#xA;Indeed, this could be used the same way, though for that secret it can&#xA;simply be placed inside the onion rather than passed alongside.&#xA;&#xA;Cheers,&#xA;Rusty.</html></oembed>