[cryptography] A question about public keys

Nico Williams nico at cryptonector.com
Sun Sep 29 15:24:39 EDT 2013

Just because curve25519 accepts every 32-byte value as a public key
doesn't mean that every 32-byte value is a valid public key (one
resulting from applying the curve25519 operation).  The Elligator
paper discusses several methods for distinguishing valid public keys
from random.


