On Wed, Sep 23, 2015 at 12:28 AM, Trevor Perrin <[email protected]> wrote:
>
> PureEdDSA would never calculate an R that equals Z.  If you choose the
> Hash carefully to avoid length-extension issues

With some sleep: I don't know why I brought up length-extension, seems
irrelevant (and "choose the Hash" was silly, because the goal was to
be back-compatible with existing signatures made with Ed25519 /
SHA512.)

I think what I suggested works in that case.

Trevor
_______________________________________________
Curves mailing list
[email protected]
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to