Steven Galbraith@EllipticKiwiAnswer is "yes", and this seems to be somewhat known to the community. In short: the equality test in the Fujisaki-Okamoto transform must be constant-time, or else can do the GPST attack. 2/310:33 AM · Aug 18, 20202 Reposts6 Likes