Post
Topic
Board Development & Technical Discussion
Re: ECDSA Weak signing
by
Yves Cuicui
on 09/09/2013, 17:14:57 UTC
the way for the attacker to check if you actually did the mistake, is by computing: d = z(s-r)-1

No just to see if r equals the x coordinate of the public key.