-
UkoeHBmoneromooo: do you recall the reason coinbase amounts are committed to with a mask of 1? from this commit monero-project/monero c3b3260
-
UkoeHBThe ringct paper says to just use `a H` for coinbase amounts (web.getmonero.org/resources/research-lab/pubs/MRL-0005.pdf section 4.2), so I'm wondering where the `1 G + a H` comes from.
-
UkoeHBis it just to avoid the commitment being the identity element?
-
moneromoooUkoeHB: so they can be treated as ringct outputs without further special cases.
-
moneromoooThe choice of identity is just to have a canonical simple well known value, it culd have been anything.
-
moneromoooI did not know a MRL paper suggested a particular one.