4 ms·
Doesn't make sense to me as well, even when fully random after 30,000 signatures you would get around 60 signatures where the nonce starts with nine zero bits.
by janmo 2y ago
Doesn't make sense to me as well, even when fully random after 30,000 signatures you would get around 60 signatures where the nonce starts with nine zero bits.
I suspect there must be something else at play here.
EDIT: the nonce is PRIVATE, so the scenario I described would not work because we wouldn't know for which of the 30k signatures the nonce starts with 9 zero bits. Makes sense now.
- gs17 2y agoIf I'm understanding correctly, the difference is between knowing you have 60 and having to try (30000!/(60! * (30000 - 60)!) combinations and seeing if they worked, which is quite a few.
- cchance 2y agoI mean the write up indicates you'd need access to the server side, or the pageant with the private key loaded, which both seem to be like... umm... at that point don't we have bigger issues?
- Khoth 2y agoNot sure about the pageant part, but it's a major problem when connecting to a compromised server leaks the client's private key. (For example, if an attacker has compromised server A and you connect to it, they can now use your key to connect to server B which you also use)
- leni536 2y agoNow I feel better for never using the same key for different servers.