[curves] Optimizing a pair of EdDSA signatures on the same message
burdges at gnunet.org
Sun Nov 8 15:50:19 PST 2015
On Mon, 2015-11-09 at 00:47 +0100, Jeff Burdges wrote:
> I warned him against dong this with x and y reversed, as then the r
> has less entropy, so repeating messages would give an attack on the
> second signature's private key.
Actually, I suppose a better way to do this is to use both private keys
when deriving r, yes?
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 819 bytes
Desc: This is a digitally signed message part
More information about the Curves