[noise] out of curve points

Jason A. Donenfeld Jason at zx2c4.com
Sat Sep 19 17:52:26 PDT 2015


 What about the case in which the responder is dealing with both a bogus
static public key and a bogus ephemeral key from the initiator? In this
case, it's likely that it's possible to massage the keys into something
unfortunate. Is it also possible to use this for leaking any *private* data
from the responder?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20150920/6b97ec93/attachment.html>


More information about the Noise mailing list