4 ms·
https://eprint.iacr.org/2017/627.pdf https://eprint.iacr.org/2017/627.pdf
by dependenttypes 6y ago
https://eprint.iacr.org/2017/627.pdf https://eprint.iacr.org/2017/627.pdf
- upofadown 6y agoThe current version of libgcrypt is not practically exploitable using the technique described in that 3 year old paper.
- dependenttypes 6y agoI remember that their changes <https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commitdiff;h=8725c99ffa41778f382ca97233183bcd687bb0ce;hp=78130828e9a140a9de4dafadbc844dbb64cb709a> https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=c... were still variable time and thus able to leak secrets. I presume that nobody bothered exploiting yet. Anyway, even if this was fixed (which I doubt it) the point is that they had vulnerable code for 18 years.