<oembed><type>rich</type><version>1.0</version><author_name>npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_name><author_url>https://nostr.ae/npub1y22yec0znyzw8qndy5qn5c2wgejkj0k9zsqra7kvrd6cd6896z4qm5taj0</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2018-09-11&#xA;📝 Original message:- Musig, by being M of M, is inherently prone to loss.&#xA;&#xA;- Having the senders of the G*x pubkey shares sign their messages with the&#xA;associated private key share should be sufficient to prevent them from&#xA;using wagner&#39;s algorithm to attack the combined key.   Likewise, the G*k&#xA;nonce fragments should also be signed with the pubkey shares.&#xA;&#xA;&#xA;&#xA;On Tue, Sep 11, 2018 at 1:27 PM Gregory Maxwell &lt;greg at xiph.org&gt; wrote:&#xA;&#xA;&gt; On Tue, Sep 11, 2018 at 5:20 PM Erik Aronesty &lt;erik at q32.com&gt; wrote:&#xA;&gt; &gt; The security advantages of a redistributable threshold system are huge.&#xA;&gt;  If a system isn&#39;t redistributable, then a single lost or compromised key&#xA;&gt; results in lost coins... meaning the system is essetntially unusable.&#xA;&gt; &gt;&#xA;&gt; &gt; I&#39;m actually worried that Bitcoin releases a multisig that encourages&#xA;&gt; loss.&#xA;&gt;&#xA;&gt; There is no &#34;non- edistributiable multisig&#34; proposed for Bitcoin&#xA;&gt; anywhere that I am aware of.&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180911/d39149db/attachment.html&gt;</html></oembed>