3 ms·
I don't know if using gmp for RSA is a good idea. I am pretty sure that gmp would open you to side channel attacks due to its operations not being constant time
by dependenttypes 7y ago
I don't know if using gmp for RSA is a good idea. I am pretty sure that gmp would open you to side channel attacks due to its operations not being constant time.
- aseipp 7y agoGMP has constant time functions for the relevant primitives you'd need to implement RSA (notably, constant-time/space modular power functionality). You'll probably still fuck it up completely anyway if you're doing it yourself, but not because of that.
- grammarxcore 7y agoI abandoned the project because I couldn't find a reasonable solution using standard Go libs that worked in a reasonable timeframe. The bottleneck is this function. math/big.addMulVVW There was some work on it recently. https://go-review.googlesource.com/q/addMulVVW https://go-review.googlesource.com/q/addMulVVW But I feel like this issue might have been ignored. https://go-review.googlesource.com/c/go/+/164966 https://go-review.googlesource.com/c/go/+/164966 It might be addressed in Go 1.14 (although it's been marked as Backlog since I last looked at that issue). https://github.com/golang/go/issues/32492 https://github.com/golang/go/issues/32492 Point being Go, like OP of this thread suggests, has some issues. This is, to me, a critical flaw preventing my teams from using Go as a primary web language. It is both consistently faster and consistently timed to make an external call to, say, gpg2 to generate a key than it is to use the opengpg lib that relies on math/big. That's nuts.