3 ms·
Well, that's a possible solution. But often FFIs pollute the reason one chooses to use obscure languages.
by max_ 2y ago
Well, that's a possible solution.
But often FFIs pollute the reason one chooses to use obscure languages.
- bluGill 2y agoTrue, but encryption should generally be an exception to that rule. Not that C is good for writing encryption, but because there are so many weird issues with encryption which can result in an implementation that passes all the test to still be severally broken. At least the C version has had a lot of experts looking at it and preventing those issues.
- tcoff91 2y agoYou shouldn't be rolling your own crypto primitives. You can completely implement the algorithm 100% 'correct' according to the research paper but introduce a side channel that could cause key extraction by an attacker. For instance, if it doesn't always take the exact same amount of time to process something, a timing attack can be used to figure out what the private key is. Always use the battle tested implementation. Power analysis, timing attacks, acoustic cryptanalysis, etc... there's many forms of side channel attacks that can be used to defeat a theoretically sound cryptosystem.