why did Ed25519 used Edward25519 instead of Curve25519 directly?
-
-
As a protocol designer I've always followed my instinct that if I use the same (or same up to birational equivalence) key for signing and DH that I'll be setting myself up for sadness of some kind. Is this in fact safe?
-
If the secret key is compromised due to an issue in your DH code, you’ll be sad because the attacker also gets a signature key, which is often a long-term key. But having the same curve for both operations doesn’t mean that you need to use the same key.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
