why did Ed25519 used Edward25519 instead of Curve25519 directly?
-
-
There's at least one point addition in EdDSA signature validation though, right? And more if batch verification is used.
-
For EdDSA specifically, yes, even though once again it’s okay if it runs in variable time. But see STROBE signatures, or qDSA instantiated with Curve25519.
- 1 more reply
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.