Re: Side-channel vulnerability in libgcrypt - the Marvin Attack
Stephan Verbücheln via Gcrypt-devel <[email protected]>
| Newsgroups | gmane.comp.encryption.gpg.libgcrypt.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello Thank you for your work and sharing your results! How about the use case of interactively authenticating to a server which is not controlled by oneself and therefore not fully trusted? Since the authentication is interactive, the timing could matter. For example, I am using my PGP key for SSH public-key authentication to github.com and alike. Regards Stephan _______________________________________________ Gcrypt-devel mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gcrypt-devel
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQRB1rjSpCJd8a7h6mNgNUJZCjx8YgUCZfRA/AAKCRBgNUJZCjx8 Yoc6AQCwwdSRy3LmQHaDJNB+Zv+YQOsFAvmPbnLt9PTB4yOspAD/eZfdVeBqmIUc benh38sb13Bfc/iYwFfHXeQ24vIjSgA= =m+Bh -----END PGP SIGNATURE-----