The Ristretto specification defines a way to do hash-to-curve. The hash-to-curve draft and other drafts (such as the one on OPRFs) recommend doing it using hashtobase+elligator2 as with Ed25519 instead. A forthcoming paper is going to propose a 3rd way. This is annoying.
-
-
Replying to @jedisct1
everything ends up being summarized in that rfc right :P?
2 replies 0 retweets 0 likes
Replying to @cryptodavidw
I know about that draft, this is what’s currently implemented in sodium. Which is conflicting with https://ristretto.group/details/elligator_in_extended.html … that maps and adds two points.
8:43 AM - 2 May 2019
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.