On Mon, 2015-11-09 at 00:47 +0100, Jeff Burdges wrote:
> I warned him against dong this with x and y reversed, as then the r
> has less entropy, so repeating messages would give an attack on the
> second signature's private key.

Actually, I suppose a better way to do this is to use both private keys
when deriving r, yes? 

Jeff

Attachment: signature.asc
Description: This is a digitally signed message part

_______________________________________________
Curves mailing list
[email protected]
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to