The Ristretto specification defines a way to do hash-to-curve. The hash-to-curve draft and other drafts (such as the one on OPRFs) recommend doing it using hashtobase+elligator2 as with Ed25519 instead. A forthcoming paper is going to propose a 3rd way. This is annoying.
-
-
Replying to @jedisct1
that's why the Ristretto specification specifies One Way, and One Way Only, to do hash-to-group, so that implementors don't need to make a choice.
2 replies 1 retweet 6 likes -
This Tweet is unavailable.
-
This Tweet is unavailable.
Replying to @armfazh
Thanks!
12:19 PM - 2 May 2019
from Paris, Ile-de-France
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.