3 ms·
Could you expand on what's dangerous in using a curve with a non-unit cofactor? I haven't heard of this as an attack vector before.
by 29jm 9y ago
Could you expand on what's dangerous in using a curve with a non-unit cofactor? I haven't heard of this as an attack vector before.
- garmaine 9y agohttps://jonasnick.github.io/blog/2017/05/23/exploiting-low-order-generators-in-one-time-ring-signatures/ https://jonasnick.github.io/blog/2017/05/23/exploiting-low-o...
- tptacek 9y agoAs a sort of hand-wavy message board explanation: you design a protocol using public-key crypto with the assumption that any given public key pairs with a single private key and with no other public or private keys. But that's not true: for both Curve25519 and in the Ed25519 signature scheme, which were designed with curves for which point validation is supposedly unnecessary and thus not performed, there are for a given curve point other points --- not valid ones, but ones for which the math will work --- that are equivalent. For the kinds of things most developers use crypto primitives for, and most of the things everyone was using them for in 2009, these distinctions are --- I'll argue --- not that important. If your transport protocol handshake blows up because of cofactors, the problem probably isn't that you didn't check curve points; it's that you designed a bad key exchange. But since I don't do cryptocurrency work, like, at all, it's easy to forget that the mainstream of what people do with signature schemes is a lot broader than it was before. I'll try to think of a way to word that and get it into the document.