Perfect secrecy of Shamir's threshold scheme
= Perfect secrecy of Shamir's threshold scheme
{c}
Conditioned on any $r-1$ shares in <Shamir's secret sharing>, each candidate secret in $\mathbb F_p$ remains equally likely. Appending $(0,N)$ to those shares determines exactly one degree-at-most-$(r-1)$ polynomial for every candidate $N$, by the nonzero <Vandermonde determinant>.