3 ms·
from the blog post: > Fortunately, Intel solved this problem… for the hyperspecific case of AES. Newer Intel CPUs (and also other vendors including ARM) now pr
by justcommenting 12y ago
from the blog post:
> Fortunately, Intel solved this problem… for the hyperspecific case of AES. Newer Intel CPUs (and also other vendors including ARM) now provide a fast, constant-time implementation of AES in hardware.
Others have pointed to particular aspects of Intel hardware that they don't believe are 'backdoored', for some definition of backdoored. One point some of these comments appear to be missing is that using things like AES-NI typically also means using things like RDRAND.
Whether you think there's any relationship between Intel's Bull Mountain and NSA'S BULLRUN is up to you, but at the end of the day, the only way any of us can know for sure whether RDRAND uses DUAL_EC_DRBG is to:
1) decide to take Intel at their word about RDRAND using only CTR_DRBG, or
2) undertake some difficult and probably-expensive hardware forensics to find out
- pbsd 12y agoDUAL_EC_DRBG would have been the dumbest possible way to backdoor RDRAND. It would also imply that Intel is somehow able to slip in circuitry able to do two 256-bit elliptic curve scalar multiplications in under 300 cycles, and pretend it is AES circuitry which would normally be orders of magnitude smaller and faster.