Understanding Risks of Non-Random Nonce in Signature Generation

3 replies 293 views
m1kes4tFull Member
Posts: 167 · Reputation: 252
#1Dec 9, 2019, 11:38 PM
Just a heads up, this is mostly for educational purposes. Always remember that the K nonce should be completely random. Don't use this script for signing actual messages. So, we start by signing two different messages like this: message 1 = "Hello, this forum" message 2 = "Hello, this forum 2" After we get the signatures and hashes, we can use them in a script to derive the private key.
4 Reply Quote Share
dan2015Hero Member
Posts: 41 · Reputation: 3344
#2Dec 10, 2019, 01:35 AM
Yeah, this whole issue comes from older software. Most modern versions have fixed these problems. Nowadays, the K nonce is generated using random.randint in the code, so it’s way safer.
4 Reply Quote Share
m1kes4tFull Member
Posts: 167 · Reputation: 252
#3Dec 10, 2019, 07:43 AM
People like to roll their own code, and we all make mistakes sometimes. A little reminder about security flaws can’t hurt, right?
2 Reply Quote Share
dan2015Hero Member
Posts: 41 · Reputation: 3344
#4Dec 10, 2019, 09:31 AM
Got it now... I was a bit confused why you brought up those old flaws. But yeah, you make a good point. Better safe than sorry.
2 Reply Quote Share

Related topics