[TLS] Re: WG Last Call: draft-ietf-tls-mlkem-08 (Ends 20 26-07-08)

Peter Gutmann <[email protected]>
Newsgroups gmane.ietf.tls
Message-ID <SYBPR01MB6336770D2D4783FF9F220FC8EEFE2@SYBPR01MB6336.ausprd01.prod.outlook.com>
Tanja Lange <[email protected]> writes:

>Maybe it just was a rethorical quations,  but here is a quick brain dump,
>sorry if I missed anybody's favoite:

All of those are implementation errors:

- If you implement known-broken crypto, it's an implementation error.
- If you implement RSA with too-short keys, it's an implementation error.
- If your implementation chooses weak primes for RSA, it's an implementation error.
- If you get RSA padding wrong, it's an implementation error.

More generally, if you implement crypto badly, it's an implementation error.
For example if I implement RSA with p = q, that's a (pretty bad)
implementation error.

Peter.
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.