Lecture 19: Elgamal Digital Signature by Christof Paar
Introduction to Cryptography by Christof Paar · 82:22
This lecture shows why "schoolbook" RSA and ElGamal signatures are unsafe as-is: an attacker can forge valid signature/message pairs without ever knowing the private key (existential forgery), and reusing the ephemera...