Oddbean new post about | logout
 IIUC somewhat similar but with musig you don't have to reconstruct the secret to sign a message, so with musig there will never be an assembled secret in one place you could steal. Every participant has their own secret and then they agree on a message and share partitial signatures that can be assembled to the complete signature.

With sss you first assemble the shared secret, then you could sign a message with it, but the assembled secret could be stolen and then your complete security is gone.