diff --git a/draft-irtf-cfrg-hash-to-curve.md b/draft-irtf-cfrg-hash-to-curve.md index e2e87e57..08516152 100644 --- a/draft-irtf-cfrg-hash-to-curve.md +++ b/draft-irtf-cfrg-hash-to-curve.md @@ -1509,7 +1509,7 @@ In particular: - The alternative hash\_to\_base function MUST NOT use rejection sampling, and it MUST output an element of F whose statistical distance from uniform is commensurate with the security level of the target elliptic curve. - It is strongly RECOMMENDED to follow the guidelines for controlling bias + It is RECOMMENDED to follow the guidelines for controlling bias given in {{hashtobase-sec}}. - The alternative hash\_to\_base function MUST support domain separation