|
|
|
|
|
by 1aqp
1085 days ago
|
|
An important point to note, that is not very obvious from the text, is that it is (very, very) difficult to retrieve ka from A=ka.P and kb from B=kb.P. For an attacker who has A and B, it's close to impossible to recover P and ka.kb.P |
|
Edit: just looked it up and the base point for curve25519 is x=9 so no point in recovering it.