<oembed><type>rich</type><version>1.0</version><author_name>npub1aeetueshkcgcx4x7uze7qteaq85d9d4c8kzrwxqmxq2rjnl5drmssu7ctd</author_name><author_url>https://nostr.ae/npub1aeetueshkcgcx4x7uze7qteaq85d9d4c8kzrwxqmxq2rjnl5drmssu7ctd</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-03&#xA;📝 Original message:Matt Whitlock wrote:&#xA;&gt; Okay, you&#39;ve convinced me. However, it looks like the consensus here is&#xA;&gt; that my BIP is unneeded, so I&#39;m not sure it would be worth the effort&#xA;&gt; for me to improve it with your suggestions.&#xA;&#xA;I need your BIP.&#xA;&#xA;We are going to implement SSS and we&#39;d rather stick with something&#xA;publicly discussed, even if it has not formally become a BIP, than&#xA;invent our own stuff.&#xA;&#xA;I&#39;ll go ahead and comment on the current proposal here.  BIP or no&#xA;BIP, I propose to finalise this spec anyway for those who want to&#xA;implement SSS now or in future.&#xA;&#xA;I agree with the recently mentioned suggestion to make non-essential&#xA;metadata, namely key fingerprint and degree (M), optional.  Their&#xA;4-byte and 1-byte fields can be added individually at an&#xA;implementation&#39;s discretion.  During decoding, the total length will&#xA;determine which fields are included.&#xA;&#xA;For example, as a compromise between usability and security, the&#xA;metadata can be supplied out-of-band, like in plain text accompanying&#xA;the Base-58 encoded share.&#xA;&#xA;Encoding for the testnet is not specified.&#xA;&#xA;Speaking of encoding, is it not wasteful to allocate three different&#xA;application/version bytes just for the sake of always starting with&#xA;&#39;SS&#39;?  It would be OK if it were accepted as a BIP, but merely as a&#xA;de-facto standard it should aim at minimising future chances of&#xA;collision.&#xA;&#xA;I&#39;d add a clause allowing the use of random coefficients instead of&#xA;deterministic, as long as the implementation guarantees to never make&#xA;another set of shares for the same private key or master seed.&#xA;&#xA;What about using the same P256 prime as for the elliptic curve?  Just&#xA;for consistency&#39;s sake.&#xA;&#xA;Also, I&#39;m somewhat inclined towards using the actual x instead of j in&#xA;the encoding.  I find it more direct and straightforward to encode the&#xA;pair (x, y).  And x=0 can denote a special case for future extensions.&#xA; There is no technical reason behind this, it&#39;s just for (subjective)&#xA;clarity and consistency.</html></oembed>