5 ms·
> "Just because an AES implementation matches the test vectors does not make it correct or safe." Actually, this does make it correct. Whether or not it is sa
by jmulho 9y ago
> "Just because an AES implementation matches the test vectors does not make it correct or safe."
Actually, this does make it correct. Whether or not it is safe depends on the application. For example, I sent my friend Bob some cyphertext that I calculated by hand with a pencil and paper using the AES algorithm. I sent it via my trusted courier Eve. It took four hours for me to do the calculation. At the last minute I started to second guess my math so I double checked it against a respected crypto library. It was fine, so I handed it off to Eve. I am pretty sure that in this application my choice to calculate the answer by hand was exactly as safe as if I had just used the library. In fact, I am so sure (given that the answers were identical), that just as Eve was walking out the door, enroute to Bob, I pulled her close and whispered in her ear: "Eve, be very careful with this cyphertext, it took me four hours to create it."
- bascule 9y agoI'll just leave this here: https://underhandedcrypto.com/2017/07/31/2017-runner-up-neville-longbottom/ https://underhandedcrypto.com/2017/07/31/2017-runner-up-nevi...
- shinigami 9y ago...what? Yes, if you compute by hand and compare with a known implementation, than it's likely you computation is correct. But this has nothing to do with test vectors. You could match all test vectors while still giving incorrect results for values not in the test vectors.
- grymoire1 9y agoAnd how do matching test vectors ensure there are no timing attacks? Or memory leaks that disclose private keys?