Skip to content

Commit

Permalink
add two sentences justifying lack of try-and-increment
Browse files Browse the repository at this point in the history
this addresses cfrg#153
  • Loading branch information
kwantam committed Oct 12, 2019
1 parent 5bb8937 commit d45fd69
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions draft-irtf-cfrg-hash-to-curve.md
Original file line number Diff line number Diff line change
Expand Up @@ -828,6 +828,12 @@ We provide implementation details for each algorithm, describe
the security rationale behind each recommendation, and give guidance for
elliptic curves that are not explicitly covered.

This document does not cover rejection sampling methods, sometimes known
as "try-and-increment" or "hunt-and-peck," because the goal is to describe
algorithms that can plausibly be made constant time. Use of these rejection
methods is NOT RECOMMENDED, because they have been a perennial cause of
side-channel vulnerabilities.

## Requirements

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
Expand Down

0 comments on commit d45fd69

Please sign in to comment.