pull down to refresh
0 sats \ 2 replies \ @ZezzebbulTheMysterious 27 Dec \ on: ⚠️ NEVER reuse Nonce bitcoin
In ECDSA, we use RFC6979 to use a deterministic nonce based on the private key and message, this prevents accidental reuse of the nonce value.
https://datatracker.ietf.org/doc/html/rfc6979
It seems these conventions have not been specified in Schnorr. We probably need an RFC or BIP on ensuring deterministic nonces in Schnorr too to ensure that wallet or library implementers do not get this wrong.
Biased nonces can lead to complete private key compromise!
https://ecc2017.cs.ru.nl/slides/ecc2017-tibouchi.pdf