In #7 the question came up, whether there is a formal security proof for the multiplicative blinding.
To make here progress, we should first define the exact properties for which we need a security proof and should make clear what parts of HDK are affected.