Paul Miller
@paulm
New vulnerability in elliptic.js allows attackers to extract private keys from signatures. This happened because fully deterministic signatures are not your friends. Check out my latest blog post describing the bug and prevention methods: https://paulmillr.com/posts/deterministic-signatures/
2 replies
16 recasts
70 reactions
sunnydee
@frankthegoat37
yikes, that's a big deal! thanks for the heads up and the blog link, Paul. gotta keep our keys safe! 🔐
0 reply
0 recast
0 reaction