3 ms·
Even let's encrypt is issuing only a handful of certificates per second. Perhaps it'd matter more if used on a per connection basis.
by rightos 9y ago
Even let's encrypt is issuing only a handful of certificates per second. Perhaps it'd matter more if used on a per connection basis.
- tptacek 9y ago1. Nobody is attacking Lets Encrypt with fault attacks. 2. If you can induce faults on Lets Encrypt's signing infrastructure you have better attacks to deploy. 3. Lets Encrypt doesn't use Elliptic Curve in the first place.
- loup-vaillant 9y agoOf course, I was only speculating about the scale required to make several thousands of signature per second. Your second point stands, though. It's probably a waste of CPU to mitigate fault attacks in a Lets Encrypt like use case.
- deleted 9y ago[deleted]
- rightos 9y agoI wasn't suggesting any of those things weren't true, merely a back-of-the-napkin estimate of the sort of load a function like this would be sufficient for.
- wolf550e 9y agoLet's Encrypt use HSMs to sign, and more than 90% of signatures produced are for OCSP, not for issuance. Though I have failed to find the link for this, I saw them publish these numbers.