Re: ECDSA attack

Martin Schanzenbach <[email protected]> Wed, 08 Mar 2023 12:52:41 +0000
Newsgroups gmane.network.gnunet.devel
Message-ID <[email protected]>
No it is not because as they note in the paper:

" Deterministic variants (e.g. deterministic ECDSA
and EdDSA [25]) make use of cryptographic hash functions to generate the
nonces and are thus inherently resistant to the attacks described here."

We use deterministic ECDSA exclusively (afaik). So unless the hash algo is broken, we are
fine.
For some reason (my guess is ignorance), bitcoin uses the
non-deterministic ECDSA variant.
Why is that a bad idea? Well because of this (and the simpler attack
where you re-use the nonce).

BR
Martin

Bernd Fix <[email protected]> writes:

> Hi,
>
> reading a recent paper (https://eprint.iacr.org/2023/305) I wonder if 
> this has any impact on GNUnet - especially GNS, which uses ECDSA 
> signatures for PKEY-signed payloads. Do we need to phase out PKEYs and 
> replace them with EDKEYs in the future?
>
> Cheers, Bernd.
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEPREGPBD5jRS9JNFHCwmY74b1m2oFAmQIhRkACgkQCwmY74b1
m2qsRRAAojwV/H/dRm7YkRh9G+kqmTUroAETX0OSJ20lTQcbj5pcUcdAK6XBYZIj
1cA0QN5hBmIwpUFlcGGYmWnJYeyUKqLyMwbKnUg4QknBDIvbJXTT7+xa5fLstsWB
EqXZ42H4AVopf9cDDC//3at8SiRTNh7asKRXjrlgGCzYefSvCO0nEU02wiHsawuc
KVXgoUfYsHV5jcDjiHUv87Uzwsp56KtANuYU4kkx4DG2VcXY9K202w05FfjBl76F
TYQP0m3LZfbUZfF/k2/qSPxRxRmu0W/t3K0J8lIpqRf2fApoQCmwUN854e+cSOg4
DFA2eDypDiVjSOSeSgrHR2rvdVWRJBXIsaolNxdaO5vZ0CYwEda+TI+wRCAKWLm8
EK9ZolcwK9Dy3ZFvyi3Px9TAICdI3f0N+owZNBB31S9e96q1psXzuNoAn8aY0zVF
UcrJh9tI5BBibajjCZYmema6qzI476/itr3+UvzeJndBYV1VgXKizpWRhdg2N4C0
DynjDOUdruX4nNGyVmmU/WyyiH33qdwbUGnWBrB9jrio4W5vklX584B04TzZwgtu
ROu5RraGz4kofol9ugX5lItS+Ai3G7+8sDMAKRu7g98VO2G7e0bOD84XpgPsn0hX
k+/8qXSri8RAytlhC8kJKBGzLi0B+dYA4U18FNyoeQf+9Slh8DM=
=cv26
-----END PGP SIGNATURE-----