There is much effort to have snark friendly hash functions, but they
wind up being fairly algebraic.  I think this says that they might not
be secure random oracles for signatures.

I doubt it'd work, but one could try to break MuSig-DN with these ideas.

Jeff



Reply via email to