cfrg/draft-irtf-cfrg-ristretto255

Call out malleability and uniformity properties

FiloSottile opened this issue · 0 comments

Encodings are unique, not malleable, but not uniform. We should probably say that in Section 4. We might also warn against relying on them being uniform in Section 7.

Relatedly, it might be worth mentioning in Section 4.2.4 that there are multiple one-way map inputs that generate the same output. We might also want to remind implementers of the importance of uniform inputs to the one-way map in Section 7.