5 ms·
> How bad is it really? Really bad. Invalid curve attacks will leak your secret key, which most old implementations (i.e. the ones likely to end up in your ha
by CiPHPerCoder 9y ago
> How bad is it really?
Really bad.
Invalid curve attacks will leak your secret key, which most old implementations (i.e. the ones likely to end up in your hardware) don't protect against.
If you reuse an ECDSA nonce, you will leak your secret key.
If you have even the smallest timing leak, guess what.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7056 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7056
https://web-in-security.blogspot.com/2015/09/practical-invalid-curve-attacks.html https://web-in-security.blogspot.com/2015/09/practical-inval...
- exabrial 9y agoI found this article helpful: https://web-in-security.blogspot.com/2015/09/practical-invalid-curve-attacks.html https://web-in-security.blogspot.com/2015/09/practical-inval... Essentially, a bunch of ECC implementations didn't do proper bounds checking and leaked data. ECC still offers a lot of benefits in terms of key size, performance, and security, however, so do your research carefully.