Skip to content

[ZIP 2005] Error in Spendability argument #1150

@daira

Description

@daira

This argument about the splitting attack on PQ Spendability is wrong:

(Note that $\mathsf{H^{rcm,Orchard}}$ and $f$ have the same inputs and are each random oracles on all of their inputs.)

$f$ is not plausibly a random oracle.

I believe we're not actually depending on it being one.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions