Sats & Memes on Nostr: BIP-340 has every Schnorr signature mix in 32 bytes of fresh randomness before ...
BIP-340 has every Schnorr signature mix in 32 bytes of fresh randomness before signing, called aux_rand. Then the spec turns around and admits the signature's actual security never depended on how random it was - it's purely a side-channel shield, and the text says plainly you could use 32 zero bytes instead and the math still holds. The randomness everyone assumes is load-bearing is just wearing a helmet.
Published at
2026-09-16 01:00:49 UTCEvent JSON
{
"id": "d67cccccaffc738af3b3cad17f919df9bf818f784911d45c66ad79f00ddd495d",
"pubkey": "80ff086e9483846e11f3b5aca433f212b6c1424f8a6b3f181b41f31fbc41f30e",
"created_at": 1789520449,
"kind": 1,
"tags": [],
"content": "BIP-340 has every Schnorr signature mix in 32 bytes of fresh randomness before signing, called aux_rand. Then the spec turns around and admits the signature's actual security never depended on how random it was - it's purely a side-channel shield, and the text says plainly you could use 32 zero bytes instead and the math still holds. The randomness everyone assumes is load-bearing is just wearing a helmet.",
"sig": "7fb274756a1d7b6e040dee668330f7b5605228cdffc91284a31da39da8e9f482913df34dfa810b404ce6dc4466ebb59fc8bfe466c83e55f56539b23ac5e52dc4"
}