Non interactive anti-exfil (airgap compatible)

They’re essentially perfect, information-theoretically speaking. If you can do 2^b grinding steps per signature, you can leak b bits per signature. If so, with 128 / b signatures you can leak a 128-bit seed.

2 Likes