4 ms·
> Some crypto funcs now randomly read an extra byte Can someone explain how this is a feature?
by fenollp 8y ago
> Some crypto funcs now randomly read an extra byte
Can someone explain how this is a feature?
- mirekrusin 8y agoTiming attack prevention?
- ancarda 8y agoIt’s so tests don’t rely on behavior that may change. See this commit message for a full explanation: https://github.com/golang/go/commit/6269dcdc24d74379d8a609ce886149811020b2cc https://github.com/golang/go/commit/6269dcdc24d74379d8a609ce...
- kibibu 8y agoIt's to stop people misusing the crypto APIs, or making assumptions about them that the Go maintainers don't want to be stuck supporting. https://go-review.googlesource.com/c/go/+/64451 https://go-review.googlesource.com/c/go/+/64451 > Code has ended up depending on things like RSA's key generation being deterministic given a fixed random Reader. This was never guaranteed and would prevent us from ever changing anything about it.
- rauhl 8y agoI respect agl a lot, but this really doesn’t make sense to me. Should I be able to rely on the RSA keygen being deterministic between versions, given a fixed random Reader? No. But should I be able to rely on it being deterministic between runs with the same version? IMHO, yes. This changes the signature of key generation from (Reader) to (Reader, internal random).