Post AEfU4WLPfCs3XS6dTk by kalle@bitcoinhackers.org
 (DIR) More posts by kalle@bitcoinhackers.org
 (DIR) Post #AEfU4WLPfCs3XS6dTk by kalle@bitcoinhackers.org
       2021-12-22T13:25:46Z
       
       1 likes, 0 repeats
       
       What's the purpose of having the nonce commitment, R, in the challenge of of a Schnorr signature?The only reason I can come up with is malleability. if R isn't part of the challenge and (R,s) is valid for a message m and key P, then (R+xG,s+x) is also valid for m and P.Are there other issues than this?ping @waxwing https://x0f.org/@waxwing/107486175670399976
       
 (DIR) Post #AEfU5BaOKQDJRmQg1A by ajtowns@mastodon.social
       2021-12-22T16:48:54Z
       
       1 likes, 0 repeats
       
       @kalle @waxwing if you make the validation function sG=R+H(P,m)P (not committing to R) you don't need the private key to sign - just choose s arbitrarily and calculate R=sG-H(P,m)P