<oembed><type>rich</type><version>1.0</version><title>Jonas Nick [ARCHIVE] wrote</title><author_name>Jonas Nick [ARCHIVE] (npub1at…y3z5a)</author_name><author_url>https://yabu.me/npub1at3pav59gkeqz9kegzqhk2v4j4r435x42ytf23pxs8crt74tuc8s2y3z5a</author_url><provider_name>njump</provider_name><provider_url>https://yabu.me</provider_url><html>📅 Original date posted:2023-07-24&#xA;🗒️ Summary of this message: Party 1 is unable to determine the final value of (R, s1+s2) or m, but a blinding step may be missing, allowing the server to scan the blockchain for signatures and compute corresponding hashes to check for a match.&#xA;📝 Original message:&#xA;&gt; Party 1 never learns the final value of (R,s1+s2) or m.&#xA;&#xA;Actually, it seems like a blinding step is missing. Assume the server (party 1)&#xA;received some c during the signature protocol. Can&#39;t the server scan the&#xA;blockchain for signatures, compute corresponding hashes c&#39; = H(R||X||m) as in&#xA;signature verification and then check c == c&#39;? If true, then the server has the&#xA;preimage for the c received from the client, including m.</html></oembed>