Stefan

Results 13 issues of Stefan

Hello, based on the implementation [here](https://github.com/matter-labs/sapling-crypto/blob/master/src/circuit/baby_eddsa.rs#L91) you only bind the message to the nonce, but not the public key. Usually in EdDSA one also binds the public key: https://tools.ietf.org/html/rfc8032#section-3.3 https://eprint.iacr.org/2015/677.pdf...

service is timing out. any plans to bring it online again?