Post
Topic
Board Development & Technical Discussion
Re: New Attack Vector
by
Sergio_Demian_Lerner
on 04/10/2012, 21:26:46 UTC
For the record, there is another possibility of signature malleability.

For every ECDSA signature (r,s), the signature (r, -s (mod N)) is a valid signature of the same message. Note that the new signature has the same size as the original, as opposite as the malleabillity of padding.