Calculation of the ten base points used for the Pedersen hash.
The ten base points used for Semaphore's Pedersen hash were chosen in a
pseudorandom fashion. In [Sema-Spec:5.3.2] these are called
generators and are denoted
The description in [Sema-Spec:5.3.2] of how the base points were chosen
is not quite correct. The input to
For eachs , the generatorg_s is computed as the first successful attempt, when incrementally trying indices fromi = 0 , at finding a\mathsf{BabyJubjub} point from a possiblex coordinate calculated as with the 255th bit set to 0.