small correction, even strengthening my line of argument.

> Twist security is only important, if you use do one of the following:
[...]
> - You transmit uncompressed points and fail to verify the curve equation. 
> Since this check is so simple and cheap, this
> would be careless.
> 
And, actually, in this case, "twist security" doesn't help you.


-- 
Johannes

_______________________________________________
Uta mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/uta

Reply via email to