Paul Miller on Nostr: We are discussing how many additional bits should one fetch in order to safely ...
We are discussing how many additional bits should one fetch in order to safely mod-div them by elliptic curve order, to get a private key. Like, 384 bits for 256-bit group.
Unfortunately, the info on the topic is limited. For example, all eddsa nonces are biased (2^-259) without explanation of security level.
Join our discussion: https://github.com/paulmillr/noble-curves/issues/71
Unfortunately, the info on the topic is limited. For example, all eddsa nonces are biased (2^-259) without explanation of security level.
Join our discussion: https://github.com/paulmillr/noble-curves/issues/71