Post
Topic
Board Altcoin Discussion
Re: Monero Pedersen commitments
by
rat4
on 16/10/2024, 11:02:28 UTC
If H = µG then µ is so-called discrete logarithm. The one who knows it can open commitment to an arbitrary value. And in particular, if H = G then µ = 1.

On the other paw, the purpose of this additional point is to ensure a hiding property. If we simplify the equation by removing it (and thus not using the masking field element), the commitment is still binding to the message, but doesn't hide it due to the lack of masking by randomness.