OK. But my gut would tell me that malleable (not pubkey prefixed) BLS sigs would be unsafe. I'm assuming by PoK you do mean BLS sigs. Wouldn't you be able to forge sigs on related keys?

Reply to this note

Please Login to reply.

Discussion

Yeah that’s a feature. You can forge the PoK on related keys. If a key has a known key then you can’t sub-exponential data with it or any related keys either.

I think I agree.

(Apart from 'key has a known key' 😁)

Haha that sentence was extremely slurred but it sounds like you got the idea!