3 ms·
Well, the Go implementation of P-256 is meant to be constant-time, even if we don't get a hard guarantee that the compiler won't screw that up somewhere somehow
by pbsd 10y ago
Well, the Go implementation of P-256 is meant to be constant-time, even if we don't get a hard guarantee that the compiler won't screw that up somewhere somehow. On the other hand, the generic implementation of the other curves is almost comically vulnerable to timing attacks---compare [1] to [2].
[1] https://github.com/golang/go/blob/master/src/crypto/elliptic/elliptic.go#L255-L263 https://github.com/golang/go/blob/master/src/crypto/elliptic...
[2] https://github.com/golang/go/blob/master/src/crypto/elliptic/p256.go#L1112-L1140 https://github.com/golang/go/blob/master/src/crypto/elliptic...