Re: Adding a nounce before hashing as covert channel

Andrew Gallagher via Gnupg-devel <[email protected]>
Newsgroups gmane.comp.encryption.gpg.devel
Message-ID <[email protected]>
On 17 Dec 2024, at 04:21, James Bottomley <[email protected]> wrote:
> 
> The EC signature nonce must be both unique and unknown (if you know it
> you can also recover the private key).  This means that if you use the
> message hash as part of a deterministic nonce scheme, you have to mix
> it with something unknown (like the private key or another random
> number).  The point being that this mixing is an attack point that can
> be faulted to make nonce re-use much more likely.


In EdDSA, this mixing is done by calculating a digest over (private key, message). Is this really a practical attack vector? How do you introduce a fault that causes a digest algorithm to produce a *known* result?

In any case, nobody is claiming that the signature salt is a magic bullet.

A

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmdhT10ACgkQXB7EBNWQ
Zilxew//VrdpXyHiRXCyMSW29CeXjAx/EngYH32oQ7nREJz4MPKSbZ/uMBsvAIB0
Np5q5iPHobcAgDYxChVqT9D4xZvJxhFVi58elYmVX2wepaqiRD7L3twCxp9TS6+2
9PWC+B3pzHIrW8o2s7hXVWAakZyyZRP6gHyp6ObzoBIEm0UHsJNVSCfPI1rM8WUm
XGSmeI/PRUsKkLEh6TAyml6SLhoMna5M7SIyxvDESbfJ4jLtZ/JxFBKLdWR36Bfu
dHOJhDaCOVKd+1wpmV3aMSL5RBkDuj9+UMVA/FQB36cmziodBejRNhO4Lz7KbuLD
1pOMqF60BIvskq6eM6DaYouCi2079NNiG5bNlhKw9Bdt3zly4a6I+HhkjY4uf3vD
itw6EYxOOqJIDFME6aP6sTeMKxed4wkD33nJwOYPYXeUZG5KZ++0T4YvwEv8Xx11
IlUy87hISvGbOT/xeELbDY2JWcRZVHj52+H7J9iz0jo2SlCUgeDJHs+SFlYRspSk
Ti9WM/CW4w+eHonHNnHRonQsTYVjNvqJu2TFpqyxCBMVkik+ZrueRwGL1csPvvxB
iHO1NmILIjLRA4/DN3d+vuE51Pu+dhkt5t3VktI76X1Tu9gMhVREzHvLeDeKnOP0
ks91KgGYWZn6PMszQtK5rVYoZXEpKKwqBWkZtj0RxfOfuJqIEs0=
=OEin
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.