Whoops, @Yubico just scored 31% on the Sony PS3 Epic Fail scale. Collect three signatures from a FIPS Yubikey and you can calculate the private key.https://www.yubico.com/support/security-advisories/ysa-2019-02/ …
-
-
Deterministic nonce generation is possible for all curves, isn't it? Besides, mandating possibly flawed curves is quite bad idea but maybe it's due to back compat.
-
It is, but it isn't the standard for most curves, and *especially* for a FIPS device I doubt they could get away with doing that. Most standards are still using horrid NSA curves, even U2F. Only very recently is ed25519 expanding beyond the space of open source software.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.