[curves] Optimizing a pair of EdDSA signatures on the same message

Jeff Burdges burdges at gnunet.org
Sun Nov 8 15:50:19 PST 2015

On Mon, 2015-11-09 at 00:47 +0100, Jeff Burdges wrote:
> I warned him against dong this with x and y reversed, as then the r
> has less entropy, so repeating messages would give an attack on the
> second signature's private key.

Actually, I suppose a better way to do this is to use both private keys
when deriving r, yes? 

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part
URL: <http://moderncrypto.org/mail-archive/curves/attachments/20151109/16afde70/attachment.sig>

More information about the Curves mailing list