[Cryptography] More efficient and just as secure to sign message hash using Ed25519?

Allen allenpmd at gmail.com
Sun Aug 2 07:24:47 EDT 2015


> What you're losing is collision resilience. For a more detailed discussion
please see our recent paper "EdDSA for more curves", page 5, paragraph
"Security notes on prehashing"

Hi Peter,

Thank you much for the reference (and for being part of the team that
designed Ed25519).  That paper is also listed on the Ed25519 website at
http://ed25519.cr.yp.to/papers.html and I should have read it! :-)

Thanks much,

Allen



More information about the cryptography mailing list