4 ms·
I only had a brief look at it but it seems that crypto_check doesn't verify whenever the signers public key is on the curve.
by flanfly 9y ago
I only had a brief look at it but it seems that crypto_check doesn't verify whenever the signers public key is on the curve.
- loup-vaillant 9y agoI'm not sure. If there is such a test, you should find it on `ge_frombytes_neg`. I bet it returns -1 in line 1315 if that happens. (It triggers a rejection when that happens.) If I'm right about this, it would explain why this code path is never hit: it would only trigger with invalid public keys. I'll test that as soon as I can.