3 ms·
There's already a named attack on kyber as well. `KyberSlash` http://kyberslash.cr.yp.to/ http://kyberslash.cr.yp.to/ as best I can tell it seems to be impl
by DeepYogurt 3y ago
There's already a named attack on kyber as well. `KyberSlash`
http://kyberslash.cr.yp.to/ http://kyberslash.cr.yp.to/
as best I can tell it seems to be implementation specific rather than about kyber as a spec, but still worth knowing about
- Analemma_ 3y agoIt's just not that they're implementation specific, but they're also side-channel timing attacks. Not that they shouldn't be discovered and fixed, but this sort of thing is kind of inevitable in the first days of a brand-new protocol, and I don't really think it deserves a named vulnerability. I can't imagine it won't be fixed in short order.
- bjoli 3y agothere is quite a heated argument in the NIST comments regarding kyber. DJB is not impressed with how they calculated some kind of security bound. The kyber folks (and maybe some others) seem to think DJB is a prick. This is so far above my pay grade that I don't know what to think. DJB has a tendency to be right, but then again: he is the kind of guy that checks the return value of printf even in non-critical paths. As one wants a crypto guy to be, I guess...
- xcdzvyn 3y agoThis page taught me Zig not only has _an_ implementation of Kyber, but an implementation of Kyber in the stdlib. There's also ECC, numerous hashes, stream ciphers... impressive!(?)[0] [0] https://ziglang.org/documentation/master/std/#A;std:crypto https://ziglang.org/documentation/master/std/#A;std:crypto
- thadt 3y agoIndeed, Zig's crypto library is on point. For example, the aforementioned KyberSlash was already patched two months ago[1], by jedisct1 (author of the inimitable libsodium). [1] https://github.com/ziglang/zig/commit/21ae64852a531c36ae3166aa2b6f1fbaaf76c6f9 https://github.com/ziglang/zig/commit/21ae64852a531c36ae3166...