A number of multisig and threshold sig key aggregation schemes developed outside of the Bitcoin ecosystem (e.g. SpeedyMuSig, FROST) use proofs of possession yet those developed in the Bitcoin ecosystem (MuSig1, MuSig-DN, MuSig2, a future Bitcoin specification of FROST too perhaps) generally avoid using proofs of possession. Why are proofs of possession generally avoided in Bitcoin schemes?

This was discussed during this online Socratic on MuSig2.


