Skip to content

Conversation

@arjanz
Copy link
Contributor

@arjanz arjanz commented Aug 19, 2022

Background

Article at https://github.com/MystenLabs/ed25519-unsafe-libs mentions potentially unsafe ed25519 signature libraries that allow a public api where secret and public key can be provided independently as signing function inputs. Misuse of these public apis can result to private key exposure.

Solution

Following Substrate on using ed25519-zebra bindings in stead of ed25519-dalek: paritytech/substrate#11781

Closes #235

@arjanz arjanz merged commit 4dd848f into master Aug 23, 2022
@arjanz arjanz deleted the az-ed25519-zebra branch August 23, 2022 12:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Swap ed25519-dalek for ed25519-zebra

2 participants