<oembed><type>rich</type><version>1.0</version><author_name>npub17qxssk9sj2r7jswvh3y32e7vwz7mcckhz33gk9nurdmw0lhsfkgswupwet</author_name><author_url>https://nostr.ae/npub17qxssk9sj2r7jswvh3y32e7vwz7mcckhz33gk9nurdmw0lhsfkgswupwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2014-04-04&#xA;📝 Original message:On Friday, 4 April 2014, at 10:51 am, Gregory Maxwell wrote:&#xA;&gt; On Fri, Apr 4, 2014 at 10:16 AM, Matt Whitlock &lt;bip at mattwhitlock.name&gt; wrote:&#xA;&gt; &gt; Honestly, that sounds a lot more complicated than what I have now. I made my current implementation because I just wanted something simple that would let me divide a private key into shares for purposes of dissemination to my next of kin et al.&#xA;&gt; &#xA;&gt; I suggest you go look at some of the other secret sharing&#xA;&gt; implementations that use GF(2^8), they end up just being a couple of&#xA;&gt; dozen lines of code. Pretty simple stuff, and they work efficiently&#xA;&gt; for all sizes of data, there are implementations in a multitude of&#xA;&gt; languages. There are a whole bunch of these.&#xA;&#xA;Okay, I will.&#xA;&#xA;&gt; &gt; Do you have a use case in mind that would benefit from byte-wise operations rather than big-integer operations? I mean, I guess if you were trying to implement this BIP on a PIC microcontroller, it might be nice to process the secret in smaller bites. (No pun intended.) But I get this feeling that you&#39;re only pushing me away from the present incarnation of my proposal because you think it&#39;s too similar (but not quite similar enough) to a threshold ECDSA key scheme.&#xA;&gt; &#xA;&gt; It lets you efficiently scale to any size data being encoded without&#xA;&gt; extra overhead or having additional primes. It can be compactly&#xA;&gt; implemented in Javascript (there are several implementations you can&#xA;&gt; find if you google), it shouldn&#39;t be burdensome to implement on a&#xA;&gt; device like a trezor (much less a real microcontroller).&#xA;&#xA;Those are fair points.&#xA;&#xA;&gt; And yea, sure, it&#39;s distinct from the implementation you&#39;d use for&#xA;&gt; threshold signing. A threshold singing one would lack the size agility&#xA;&gt; or the easy of implementation on limited devices.  So I do think that&#xA;&gt; if there is to be two it would be good to gain the advantages that&#xA;&gt; can&#39;t be achieved in an threshold ECDSA compatible approach.&#xA;&#xA;I agree. I&#39;ll look into secret sharing in GF(2^8), but it may take me a few days.</html></oembed>