Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Update draft-irtf-cfrg-det-sigs-with-noise.md
Fixed a hypothetical attack where an attacker is able to induce a nonce collision between Hedged Ed25519 and Hedged Ed25519ctx by completely controlling Z and setting the context value to empty The new construction aligns more with the first part of #3 since dom2 and dom4 of RFC 8032 are potentially variable length. Added domain separation with dom2 and dom4 of RFC 8032 through leading 0x00 byte.
- Loading branch information