top | item 46035371

(no title)

chc4 | 3 months ago

They're vulnerable to "High-S" malleable signatures, while ed25519 isn't. No one is claiming they're backdoored (well, some people somewhere probably are), but they do have failure modes that ed25519 doesn't which is the GP's point.

discuss

order

No comments yet.