This channel is for discussing theoretical ideas with regard to cryptocurrencies, not about short-term Bitcoin development
<ZmnSCPxj> If I needed a blind signing scheme for bearer signatures, what would be best and why? Also it seems Schnorr blind signing is vulnerable to Wagner attacks, can anyone point to some convenient treatise on such?
<sipa> ZmnSCPxj: have you seen
<ZmnSCPxj> thank you, thus you would suggest the use of Schnorr blind signing, suitably modified as per this paper?
<sipa> i'm probably not the best person to ask, but it sounds like that paper gives a pretty convincing argument that with that modification they're actually secure
<sipa> using AGM in the proof is unusual, but imho it's not a crazy model
