On Tuesday 19 May 2009 08:14:36 pm David-Sarah Hopwood wrote: > Correction: for ECDSA there are two options -- q is prime, or > q = 2^m. Right. If q=2^m (which was specified in the LAFS paper, IIRC) then the distribution of x*y mod q is not uniform. If q is prime, then this problem disappears. Shawn.