On Wed, Sep 23, 2015 at 12:28 AM, Trevor Perrin <[email protected]> wrote: > > PureEdDSA would never calculate an R that equals Z. If you choose the > Hash carefully to avoid length-extension issues
With some sleep: I don't know why I brought up length-extension, seems irrelevant (and "choose the Hash" was silly, because the goal was to be back-compatible with existing signatures made with Ed25519 / SHA512.) I think what I suggested works in that case. Trevor _______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
