4 ms·
Thanks for posting this, I came here to post the same thread. For those who are unaware: Thomas Pornin is a professional cryptographer. He's a member of the NC
by throwawaymath 7y ago
Thanks for posting this, I came here to post the same thread.
For those who are unaware: Thomas Pornin is a professional cryptographer. He's a member of the NCC Crypto Services team and one of the authors of the Sosemanuk stream cipher, which was part of the final portfolio for eSTREAM. He's also involved in the development of one of the cryptosystems which has made it to round 2 of the ongoing NIST PQCRYPTO standardization process.
His writing on crypto.stackexchange is prolific and highly informative, and this is a strong rebuttal in particular.
- nmadden 7y agoHe is also the author of https://www.bearssl.org/ https://www.bearssl.org/
- throwawaymath 7y agoNice, I forgot that one. BearSSL is one of only two TLS implementations (if I recall correctly) that wasn't vulnerable to the most recent Bleichenbacher attack variant.
- tptacek 7y agoThat's correct, BearSSL and BoringSSL (Google's OpenSSL fork). Pornin is a bad-ass. But keep in mind that they were targeting C/C++ libraries, so we don't have telemetry on (for instance) Go's crypto/tls or whatever Rust is doing with ring.