3 ms·
Having FIPS validated Rust Crypto is great and all but I'm mostly excited about pure rust Crypto :)
by sontek 3y ago
Having FIPS validated Rust Crypto is great and all but I'm mostly excited about pure rust Crypto :)
- api 3y agoNot sure this can be done without using at least a tiny bit of unsafe since many algorithms will be slow without using CPU accelerator instructions. Other algorithms are much more efficiently implemented using vector instruction sets that usually require unsafe.
- nrabulinski 3y agoUnsafe rust is still pure rust
- kibwen 3y agoAnd note that if you implement crypto in Rust by calling out to a C library, that requires the unsafe keyword anyway.
- ori_b 3y agoMore to the point, often you need assembly to prevent the compiler from sabotaging your carefully constant-time algorithms, replacing your careful length-independent XOR loops with branches and the like. Performance is a small part of why crypto code is often written in assembly. C is simply too high level, allowing too many optimizations. For that matter, assembly is too high level, and Intel is adding flags to turn off some of the internal CPU optimizations: https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/best-practices/data-operand-independent-timing-isa-guidance.html https://www.intel.com/content/www/us/en/developer/articles/t...
- IshKebab 3y agoYeah I always thought there should be a compiler annotation for that. It could automatically verify that your code really was constant time too.