Re: Side-channel vulnerability in libgcrypt - the Marvin Attack

Stephan Verbücheln via Gcrypt-devel <[email protected]>
Newsgroups gmane.comp.encryption.gpg.libgcrypt.devel
Message-ID <[email protected]>
Hello

Thank you for your work and sharing your results!

How about the use case of interactively authenticating to a server
which is not controlled by oneself and therefore not fully trusted?
Since the authentication is interactive, the timing could matter.

For example, I am using my PGP key for SSH public-key authentication to
github.com and alike.

Regards
Stephan

_______________________________________________
Gcrypt-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gcrypt-devel
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQRB1rjSpCJd8a7h6mNgNUJZCjx8YgUCZfRA/AAKCRBgNUJZCjx8
Yoc6AQCwwdSRy3LmQHaDJNB+Zv+YQOsFAvmPbnLt9PTB4yOspAD/eZfdVeBqmIUc
benh38sb13Bfc/iYwFfHXeQ24vIjSgA=
=m+Bh
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.