fn verify_signature_software(&self, data: &[u8], signature: &[u8; ED25519_SIGNATURE_LENGTH]) -> bool {
let mut h = [0u8; 64];
let data_hash = self.compute_sha512(data);
for i in 0..32 {
h[i] = data_hash[i];
}
self.verify_ed25519_reduced(h, signature)
}
This calls [1] which merely performs a byte equality check on the first 32 bytes of the hash: fn verify_ed25519_reduced(&self, h: [u8; 64], signature: &[u8; ED25519_SIGNATURE_LENGTH]) -> bool {
// ...
let mut matches = true;
for i in 0..32 {
if signature[i] != h[i] {
matches = false;
break;
}
}
// ...
matches && key_valid
}
With this design, an adversary who knows data can simply calculate their own hash of the input data and supply it as a "signature", no?It is difficult to comment on the verification approach when there are no secrets and only hash verification occurs. Do you have documentation on the approach and future plans? At best, this "signature verification" looks like placeholders for future verification.
[0]: https://github.com/JGiraldo29/vekos/blob/d34e6454f3f7290e4b5...
[1]: https://github.com/JGiraldo29/vekos/blob/d34e6454f3f7290e4b5...