BLUE
TH
Tjaden Hess
@tjade273.bsky.social
19 followers44 following8 posts
THtjade273.bsky.social

Any idea why they use this pedersen hash nickname*G1 + discriminator*G2 + H(nickname, discriminator)*G3 rather than just H(nickname, discriminator)*G along with a simple Schnorr proof? I can’t think of any properties the former gives over the latter

1

Sstr4d.xyz

The discriminator acts like a blinding factor in a Pedersen commitment to the nickname (with 30 bits of possible entropy, which is then reduced down to a minimum of 7 bits due to their UX desire to pick a minimal-length discriminator), and then the hash itself acts like a full-width blinding factor.

2
TH
Tjaden Hess
@tjade273.bsky.social
19 followers44 following8 posts