bitcoin-dev

Schnorr signatures BIP

Schnorr signatures BIP

Original Postby Erik Aronesty

Posted on: September 5, 2018 13:14 UTC

In a discussion about an M-of-N Bitcoin multisig scheme, it was noted that there is an interaction step to deduce Gk when signing, and each participant must publish Gki.

This interactive step does not break the scheme, but it is not non-interactive. One person in the discussion questioned why there was so much hemming and hawing about the scheme, saying that it seemed trivial. However, others in the discussion pointed out that the scheme has been repeatedly shown to be flawed, with the person promoting it failing to implement it correctly and causing confusion in the public eye. They noted that the person promoting the scheme had been told multiple times that it doesn't work, but continued to post incomplete and incoherent copies of it across various platforms. The flaws in the scheme were explained, with one issue being that there is no possible value for 'k' from which 'R' is derived in the signing procedure, and individual signers cannot learn 'R' at signing time without interaction. Despite this, the person promoting the scheme seemed to continue to ignore the issues with it.