Ed25519 "clamping" and its effect on hierarchical key derivation

Trevor Perrin trevp at trevp.net
Tue Mar 28 17:35:32 PDT 2017

On Tue, Mar 28, 2017 at 5:25 PM, Trevor Perrin <trevp at trevp.net> wrote:
> So maybe the question is how much you care about spending a little
> extra effort in key derivation to make the keys a little safer with
> existing DH software?  I.e., do you multiply by the scalar as part of
> derivation, or leave that for a future DH operation?

typo in last sentence: "multiply by the *cofactor*".


