- polynomial nonces okay because you need honest majority anyway for BFT consensus
- PoK/commit-reveal could be better than noncehash for better flexibility (or noncehash that doesn't commit to signing set or message)
- stinsons and strobl only has proof for passive adversary
- do we want to commit to the FROST group key explictly in the sig with a tweak?
Last active
August 29, 2025 14:35
-
-
Save jesseposner/673c9fbc9d10b7abbe8f128c3165d948 to your computer and use it in GitHub Desktop.
FrostyMuSig
Author
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
threshold trick: AB, BC, CA -> generalizes to n-1 of n