pub fn combine(shares: &[PrgShare], nonce: &[u8]) -> [u8; 32]
Combine T PRG shares (XOR) to produce the true random output.