Paul Miller
@paulm
New vulnerability in elliptic.js allows attackers to extract private keys from signatures. This happened because fully deterministic signatures are not your friends. Check out my latest blog post describing the bug and prevention methods: https://paulmillr.com/posts/deterministic-signatures/
2 replies
11 recasts
53 reactions
raquo
@raquo.eth
luckily k reuse is a well-known vuln and research into real world data (from myself and independent researchers) have shown it’s very very rare
1 reply
0 recast
0 reaction
Paul Miller
@paulm
Past performance is not indicative of future results
0 reply
0 recast
0 reaction