>There are several ways to sign a document with EdDSA, and produce a valid signature. The three sources of malleability are:
>We can add a multiple of L (the order of the prime subgroup) to s. Recall that B has order L as well, so it will absorb any cofactor. Basically everything happens modulo L, so adding L won't change a thing.
This is prevented in RFC 8032 by checking that 0 <= s < L. Tink [1] does this check, and therefore is malleability free.
>We can sign the same message with a different nonce r. This requires knowledge of the secret key a.
This proves that the signature of a message is not unique -- that is the signer can product multiple signatures -- but I haven't seen anyone calling this a malleability issue. Malleability is about taking a triple (public key, signature message) and tweaking bits to produce another valid triple.
>We can add a low order point to A, and subtract it from R. That way we produce a valid signature, but from a public key nobody vouches for. If the verifier checks the weaker equation, we can add a low order point to just R, and produce a "valid" signature with the same public key.
This is the second time I saw this claim. When I first saw it [2], I thought, wait, this test is missing in Wycheproof [3], but Bleichenbacher does NOT miss anything. That's when I knew it's wrong.
Modifying A or R instantly makes the signature invalid. Using the article's notation, the signature is validated by checking that
B.s.8 == R.8 + A.h.8, where h = SHA-512(R, A, M) and M is the message
Multiplying the cofactor or not doesn't matter, doesn't introduce any weakness, as implied by the article. If R or A is changed, h will change.
[1] https://github.com/google/tink
[2] https://github.com/dalek-cryptography/ed25519-dalek/issues/2...
[3] https://github.com/google/wycheproof. Wycheproof has tests for EdDSA malleability, but it only tests if s is not properly range checked.