9 ms·
Good point! If I update the post to indicate that the length is also checked in secvfy.c: http://www.koders.com/c/fid7EBD6C04C1D001D6410ED86171294E237E35273E.as
by moserware 17y ago
Good point! If I update the post to indicate that the length is also checked in secvfy.c: http://www.koders.com/c/fid7EBD6C04C1D001D6410ED86171294E237E35273E.aspx#L74 http://www.koders.com/c/fid7EBD6C04C1D001D6410ED86171294E237...
and link to the matasano series, would that better address your concern?
- tptacek 17y agoDon't link to that source code. Mozilla's RSA implementation is really hard to follow. The most important security check there is nowhere near the function you've linked to. The "length" of the block isn't the issue (the "length" is the key size); verifying that every bit of the expected m block matches, bit for bit, with the received m block is. Don't get me wrong. Great article. It has to be possible for general practitioners to write about encryption without inciting people to write their own, the same way it has to be possible for general practitioners to write about brain surgery without inciting people to cut other people's heads open. You didn't intend this as an implementation guide. =)
- moserware 17y agoThanks for the kind words! It's humbling to have a security pro like you even read it :). I dabble with this stuff because I find it interesting (especially the number theory). The Wireshark'ing was to see how things really worked. Hopefully the links I made to the Netscape and Debian OpenSSL RNG fiascos along with at least some coverage of how many subtle checks the handshake performs terrifies people enough to follow the exhortation I put at the end: "It's certainly better to use TLS than inventing your own solution."
- tptacek 17y agoMost developers would probably find Crypt++'s implementation of RSA verification --- or even, gag, LibTomcrypt --- a better rundown of how to do this safely. Too much of Mozilla NSS's functionality is scattered across multiple modules and indirected through function pointers.
- spicyj 17y agoForgive my naïvety, but what's wrong with LibTomCrypt? And did you mean Crypto++?
- moserware 17y agoI went ahead and added a link in that paragraph to your signature forgery series since I wasn't aware of that attack.