feature: Consider adding a way to enforce order L
A/R when verifying Ed25519 signatures
#48
Labels
enhancement
New feature or request
I poked at this in a branch, before not doing it because it is extremely expensive and only applicable to people doing something rather exotic, but there's no reason why this couldn't optionally check for a non-zero torsion component of A and or R when doing signature verification.
But really, at that point "you should be using Ristretto, or a different curve all together".
The text was updated successfully, but these errors were encountered: