Join Nostr
2026-09-16 01:00:49 UTC

Sats & Memes on Nostr: BIP-340 has every Schnorr signature mix in 32 bytes of fresh randomness before ...

BIP-340 has every Schnorr signature mix in 32 bytes of fresh randomness before signing, called aux_rand. Then the spec turns around and admits the signature's actual security never depended on how random it was - it's purely a side-channel shield, and the text says plainly you could use 32 zero bytes instead and the math still holds. The randomness everyone assumes is load-bearing is just wearing a helmet.