-
who-bizhey guys - I submitted a hackerone report about this some time ago - and as I'm researching a bit more I thought it best to open it for discussion (not looking for a bounty or anything)
-
who-bizIn my independent work, I found that using a hex-encoded value of zero to seed privkey generation, generates a private key = rct::identity
-
who-bizafter learning some more about algebraic group models (multiplicative).. I'm curious if anyone else sees an issue with a private key = rct::identity... if its not a problem (anonimal gave me a "thanks" on H1, moneromoooo said it was not a vuln but wrote a soft-check into codebase to prevent users from doing this)
-
who-bizcan anyone explain why it is not an issue? or weigh in on possible problems with allowing keys = identity?
-
moneromoooIf anyone sees an issue with 0, they'll see an issue with 1. And if with 1, then 2, etc.
-
who-bizI
-
who-bizSorry, not saying there is an issue. I am just curious as to others' thoughts on this.
-
who-bizI don't have anything indicating it may mess with the math. Is a key = 1 the same as a point at infinity? I get the feeling I am conflating things there
-
who-bizWe didn't discuss a whole lot - and a soft-disallow seemed fine to me. I am more interested in what issues it could present, or why it doesn't. I am not a group theory mathematician but am seeking to understand things
-
who-bizI don't know that 0, or 2, are issues. But 1 seems a unique case to me
-
who-bizon a non-tech/math note - is anonimal still around?
-
moneromoooNot that I know of.
-
who-bizgood to see you still around btw!
-
who-bizit has been a few years :)
-
who-bizlogging off, but will monitor logs for discussion. thanks folks