4 ms·
> Yes, side channels can be a nightmare to track down I think that this is extremely overrated. As long as you are using C (rather than some weird language), a
by dependenttypes 6y ago
> Yes, side channels can be a nightmare to track down
I think that this is extremely overrated. As long as you are using C (rather than some weird language), avoid branches with secrets, avoid indexing arrays with secrets, and avoid *, division, and mod with secrets it should be fine.
> https://twitter.com/bascule/status/1287113393439035392 https://twitter.com/bascule/status/1287113393439035392
Low quality posts like that which encourage dunking on people rather than discussion are what made me stop using twitter. Extremely disgusting on his part, I am sorry that you have to deal with this sort of bullying. (I also did not find any signed shift despite the claim of the person responding)
- loup-vaillant 6y agoAgreed, timings are not too hard to address in C. Though I confess I gave up on multiplication. Monocypher's manual warns users about that, but I can't avoid it without incurring unacceptable slowdowns on most platforms. The other side channels however I gave up on them: only custom silicon can meaningfully squash the energy consumption side channel for instance. Software approaches are in my opinion brittle mitigations at best. About Twitter, I may have overplayed it: I don't use it, so I mostly don't see these things, which in reality are really infrequent. The worst I got was at the time I disclosed the signature vulnerability. It was like a dozen tweets, and only a couple were openly mocking (for the anecdote, I only saw those tweets a year later). In any case, I don't give them much weight: writing this kind of drivel requires some degree of ignorance about my work.
- DarthGhandi 6y ago> As long as you are using C... These things mentioned are what frustrate me with crypto implementations in pure Rust, the attempts at constant time operations aren't that solid and everyone is going to war with the compiler to simply get basic functionality. Replacing pointer arithmetic where it's needed with array indexing stands out the most but there's other issues. Honestly think just using C bindings and calling it day is the best way for anything going into production.
- zenhack 6y ago> Replacing pointer arithmetic where it's needed with array indexing stands out the most but there's other issues. What situations do you run into where array indexing is not an acceptable substitute for pointer arithmetic?
- loup-vaillant 6y agoFor the record, implementing Monocypher was not one of them. I use arrays everywhere. The one borderline case I can cite is wiping memory. I go by sizeof() and access each byte.