Paul Miller
@paulm
New vulnerability in elliptic.js allows attackers to extract private keys from signatures. This happened because fully deterministic signatures are not your friends. Check out my latest blog post describing the bug and prevention methods: https://paulmillr.com/posts/deterministic-signatures/
2 replies
11 recasts
59 reactions
anna jørgensen
@neojho
whoa, that's wild! thanks for the heads-up, paul. definitely gonna read your blog post. gotta keep those keys safe! 🔐
0 reply
0 recast
0 reaction