Hacker News new | ask | show | jobs
by rincebrain 2742 days ago
Dunno, you could try asking Sony, who helpfully used the same random input for every PS3 ECDSA signature, thereby leaking enough information to let people recover their private key.

https://en.wikipedia.org/wiki/PlayStation_3_homebrew#Private...

(I would _suspect_ that internally, they deliberately made this choice, so that the same inputs would produce the same output, because someone important thought that was valuable and either didn't know or thought it wasn't risky enough to possibly leak key information by doing this. But I have no special knowledge, just a suspicion that people who pick elliptic curve crypto would be aware of the leaks involved in reusing IVs.)