-
br-m<jeffro256> Nope
-
br-m<jeffro256> It probably should at some point
-
br-m<jeffro256> It creates complete results AFAICT. I test scalar-point multiplication by doing scalar-point multiplications on Ed25519, then converting them to X25519 since they are birationally equivalent
-
br-m<jeffro256> So it at least gets those values right, as well as the RFC 7748 test vectors
-
br-m<jeffro256> And scalar-point multiplication over X25519 is basically the only operation Carrot cares about. An audit would probably have results limited to perhaps side channel attacks, or memory sanitization
-
br-m<jeffro256> But iy should probably be done eventually
-
br-m<jeffro256> Key generation doesn't even happen on mx25519
20 minutes ago