<oembed><type>rich</type><version>1.0</version><title>Tom Trevethan [ARCHIVE] wrote</title><author_name>Tom Trevethan [ARCHIVE] (npub1ax…wyw7n)</author_name><author_url>https://yabu.me/npub1axshsyxsl3vasj4z9549rvwdvhjmh52fw0ayj3ghtmdezx8cnuxqlwyw7n</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>📅 Original date posted:2023-07-26&#xA;🗒️ Summary of this message: Proving knowledge of the r values used in generating each R can prevent the Wagner attack, not signing or secret keys.&#xA;📝 Original message:&#xA;Not &#39;signing&#39; but &#39;secret&#39; i.e. the r values (ephemeral keys). Proof of&#xA;knowledge of the r values used to generate each R used prevents the Wagner&#xA;attack, no?&#xA;&#xA;On Wed, Jul 26, 2023 at 8:59 PM Jonas Nick &lt;jonasdnick at gmail.com&gt; wrote:&#xA;&#xA;&gt; None of the attacks mentioned in this thread so far (ZmnSCPxj mentioned an&#xA;&gt; attack on the nonces, I mentioned an attack on the challenge c) can be&#xA;&gt; prevented&#xA;&gt; by proving knowledge of the signing key (usually known as proof of&#xA;&gt; possession,&#xA;&gt; PoP).&#xA;&gt;&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20230726/05286983/attachment-0001.html&gt;</html></oembed>