Paul Miller
@paulm
New vulnerability in elliptic.js allows attackers to extract private keys from signatures. This happened because fully deterministic signatures are not your friends. Check out my latest blog post describing the bug and prevention methods: https://paulmillr.com/posts/deterministic-signatures/
2 replies
8 recasts
51 reactions
dreamy_wander3ršāØ
@nmains356
whoa, that's wild! š² never thought deterministic signatures could backfire like that. gonna check out your blog for sure, paul! thanks for the heads up! šāØ
0 reply
0 recast
0 reaction