Fix BLS pop dst and no context API - #695
Open
perturbing wants to merge 5 commits into
Open
Conversation
perturbing
force-pushed
the
perturbing/fix-bls-pop-dst
branch
from
August 18, 2026 09:16
67e7161 to
30a51d9
Compare
ch1bo
approved these changes
Aug 18, 2026
ch1bo
left a comment
Contributor
There was a problem hiding this comment.
Can we make the API simpler for the normal signature case too?
|
Identified and reported by Anastasia Labs. 🫡 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
In the IETF draft of BLS signatures, the domain separation tag of the proof of possession should be separated from normal signatures. E.g., this means we should use the prefix tag
BLS_POP_for the PoP andBLS_SIG_for signatures (which we already did).Before, we used the
BLS_SIG_prefix for PoP as well; this is insecure as you can trick a key holder into signing a PoP without that intent via the signature path(can be useful in a rogue key attack).This PR also fixes a typo in the Curve family description.
Credits to @colll78
Checklist
CHANGELOG.mdfor the affected packages.New section is never added with the code changes. (See RELEASING.md)
.cabalandCHANGELOG.mdfiles according to theversioning process.
.cabalfiles for all affected packages are updated.If you change the bounds in a cabal file, that package itself must have a version increase. (See RELEASING.md)