You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I had recently introduced a loop bound for rejection sampling during signing (cf. #558). Going from the comment in the code I went for a bound of 576 attempts, which should give a failure probability of less than 2^-128. However, the standard actually prescribes a higher mandatory minimal number of attempts, giving a failure probability less than 2^-256.
The text was updated successfully, but these errors were encountered:
I had recently introduced a loop bound for rejection sampling during signing (cf. #558). Going from the comment in the code I went for a bound of 576 attempts, which should give a failure probability of less than 2^-128. However, the standard actually prescribes a higher mandatory minimal number of attempts, giving a failure probability less than 2^-256.
The text was updated successfully, but these errors were encountered: