i think you can do it:
pre-agree on a bit string c
you pick a value a and compute H(a) where H is a cryptographic hash function
then the tuple (a, H(a)) is proof that you (probably) don't know the preimage of H(a) XOR c
i don't know why you'd want that, but you could
You’re unable to view this Tweet because this account owner limits who can view their Tweets. Learn more

