A secure implementation should use more explicit domain separation for hash functions used for commitment mask recovery.
A secure implementation should use more explicit domain separation for hash functions used for commitment mask recovery.