Tags: sympy ecdsa forgery 


**Full write-up:** [https://www.sebven.com/ctf/2021/08/23/corCTF2021-LCG_k.html](https://www.sebven.com/ctf/2021/08/23/corCTF2021-LCG_k.html)

Cryptography – 489 pts (25 solves) – Chall author: qopruzjf

When it comes to signatures, proper randomness is essential. A standard Linear Congruential Generator is not good enough, not by a long shot. In fact, we only need a total of four signatures from the server to completely break it and be able to forge any signature we want ourselves.

