Re: Side-channel vulnerability in libgcrypt - the Marvin Attack
Hubert Kario via Gcrypt-devel <[email protected]>
| Newsgroups | gmane.comp.encryption.gpg.libgcrypt.devel |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
On Friday, 22 March 2024 00:51:06 CET, NIIBE Yutaka wrote: > Hello, > > And... yes, it's true that it's hard for programming to estimate > worst-case running time, it's also hard to guarantee constant-time > running time, in a given situation of programming environment and > hardware architecture. OpenSSL, BoringSSL (they have different code for RSA than OpenSSL now), Go, NSS, GnuTLS, Apple corecrypto, and WolfSSL were all able to do this operation in constant time in software, and those are only the ones that I have directly seen the evidence that the fixes were successful, so while it may not be simple, it's clearly not impossible. -- Regards, Hubert Kario Principal Quality Engineer, RHEL Crypto team Web: www.cz.redhat.com Red Hat Czech s.r.o., Purkyňova 115, 612 00, Brno, Czech Republic _______________________________________________ Gcrypt-devel mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gcrypt-devel