[curves] Degenerate Curve Attacks

Ben Harris mail at bharr.is
Mon Dec 28 12:02:50 PST 2015


On 29 Dec 2015 5:35 am, "Ron Garret" <ron at flownet.com> wrote:
> On Dec 28, 2015, at 10:28 AM, Trevor Perrin <trevp at trevp.net> wrote:
>
> > New paper:  https://eprint.iacr.org/2015/1233
> >
> > Anyone able to summarize the practical implications?
>
> Validate your curve points and you should be fine.

Or use point compression (which achieves the same thing, at least in the
twisted Edwards case).
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/curves/attachments/20151229/b671170a/attachment.html>


More information about the Curves mailing list