Score:2

What is the advantage of ECDSA over Schnorr signature?

ie flag

As we know, the Schnorr signature enjoys the linearity property, which does not exist in ECDSA. It seems the Schnorr signature is more efficient and can bring more features than ECDSA. What is the advantage of ECDSA over the Schnorr signature? Will ECDSA gradually be replaced by the Schnorr signature (especially after that the Schnorr signature can be used in Bitcoin)?

kelalaka avatar
in flag
[Performance of ECDSA, ECKCDSA and ECGDSA](https://crypto.stackexchange.com/a/57577/18298) (Last paragraph) Inversion-free alternative. May I interest you in the Schnorr-based EdDSA, which avoids inversions altogether for signing and verification, and is widely available in high-quality software running in constant time with defense against broken random number generators at signing time?
kelalaka avatar
in flag
Schnorr signature doesn't need an inverse, ECDSA is vulnerable to tiny bias on the $k$. ECDSA is already replaced in many places to [deterministic ECDSA](https://www.rfc-editor.org/rfc/rfc6979) ( thanks to our bear)
user77340 avatar
ie flag
So you mean there is indeed no advantage of ECDSA over Schnorr signature?
user77340 avatar
ie flag
EdDSA is inversion-free, but Bitcoin/Ethereum does not support EdDSA.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.