That's what we did to get the PS3 signing keys. Accidentally became a bit of a citation in the ECDSA world for that one too; who knew Sony would unwittingly earn the title of "canonical example of how to screw up ECDSA in a consumer product"? :-)
It's also how lots of Bitcoin have been taken away when transactions are signed using broken random number generators. These days people are running bots to spot those keypairs and automatically take the bitcoin.
That's false.
Dr Nicolas Courtois - "Well, uhhhum that's the question."
Craig Wright told him that he used non-standard nonces, not predictable ones.
Edit: I see. It's confusingly worded but that makes sense.
There is a better way: make the nonce a hash of the message signature and the private key. That way you don't need any randomness, and the entire algorithm is deterministic. It is guaranteed (assuming the hash is good, but you need a good hash algorithm to sign things anyway) that no two messages will be signed with the same nonce, and that the nonce cannot be guessed without already having the private key. This is what EdDSA does.
One could just as well implement something EdDSA compatible with insecure nonce generation and people have done so (for years the thing you got when you goggled for eddsa python was just such an implementation).
It's good that the eddsa paper specifies more of the system, as people have made bad choices and ruined the security-- but even it fails to completely specify the system: the exact input handling isn't specified, which has resulted in security problems.
It's not just about specifying more of the standard either. EdDSA is designed to be harder to screw up an implementation of, by construction.
While I not a FIPS certification expert by any means, it was intended that implementations could implement RFC6979 without breaking the standard by simply using a standard allowed DRBG in the right way.
> EdDSA is designed to be harder to screw up an implementation of, by construction.
That's the marketing claim at least. It's debatable. Some of its choices make it easier to screw up, and widespread implementations of it have also been wrong in the varrious ways it was intended to address. It's a good idea to try, at least, for sure.
I think nonce security in particular is not at all the best example since modern ECDSA implementations are secure against in that respect. I'm also aware of some systems which have had grave security flaws because they believed the EdDSA claim of a deterministic signature meant that it was a unique signature. The promotion of EdDSA itself as magic pixie dust creates vulnerabilities.
There is just no replacement for understanding. :)
You can, but you can also do a lot more than that. Thinking that this is the only attack is a common error, and precisely the one Wright was making in that recording.
Two signatures with different messages and the same key and message is just a special case of the fact that if you write out the signing equation as a linear system with privkey and nonce being unknown, and the message and signatures being the knows if the resulting matrix is exactly determined or over-determined, then you can solve for the unknown values.
It would also be the case that if you had two signatures with the same key and the nonces being any known multiple of each other that it's just as solvable.
There are other attack approaches, for example if you have a set of signatures where you know the leading bits of the nonce you can also recover the keys by solving a hidden number problem. (If you only know the single leading bit it'll take a few hundred signatures).
Cryptosystems are inherently fragile. The security assumptions of these schemes demand a uniformly random nonce. Deviation from the required property easily destroys security in practically exploitable ways.
The person Wright was arguing with was pointing out that if Wright had the private keys in question -- turns out he didn't-- it wouldn't be impossible that he obtained them after observing a single insecurely generated signature. Wright drove the discussion down a tangent with an argument that one couldn't recover a key with a single signature-- a false claim, but even if it were true it wouldn't really have supported his case.