bitcoin-dev

Schnorr signatures BIP

Schnorr signatures BIP

Original Postby Andrew Poelstra

Posted on: September 5, 2018 13:05 UTC

In an email exchange, Erik Aronesty asked why people were calling his M of N Bitcoin multisig scheme FUD.

He claimed that the more he looked into it and spoke to professors, the more it seemed "so trivial nobody really talks about it." He provided a link to a Medium article with detailed explanations and code snippets. Andrew Poelstra responded by explaining that people have repeatedly told Aronesty that his scheme doesn't work and have requested that he implement it in a computer algebra system so that they can see where his mistake is. Instead, Aronesty has been posting incomplete/incoherent copies of the same thing across multiple mediums, which is distracting, offensive, and causes confusion in the public eye. Poelstra stated that Aronesty's posts are FUD. In the linked post, Poelstra found that not one of the instances of the character 'k' defined the value 'k' from which 'R' is derived in the signing procedure. He explained that there is no possible value, individual signers cannot learn 'R' at signing time without interaction, and that Aronesty's whole scheme is broken. Given the number of times Aronesty has been told this, Poelstra finds it hard to believe that it was an honest mistake.