Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
j08ny
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
j08ny
7y ago
Right, there are many ways to do it correctly. In general, you need complete addition formulas (those that can take the point at infinity and produce a correct result in a side-channel indistinguishable way), if you have those, almost any s
2.
▲
by
j08ny
7y ago
We are working on lowering that number :) It is quite a conservative estimate, we didn't want to claim something our PoC couldn't deliver. Also, it is with minimal attack runtime, as in, after you have those signatures and timings
3.
▲
by
j08ny
7y ago
If my two cents count, I would say that if you were to implement EdDSA from the paper, you would have a good chance of creating a secure implementation w.r.t. to this kind of leakage. However, if you were starting with some Short-Weierstras
4.
▲
by
j08ny
7y ago
Thanks, a paper is being prepared with the full details and an improved method. The sensitivity of the method to noise (one bad inequality in the lattice can make it not find the key) is really worth looking at, as that would improve the nu
5.
▲
by
j08ny
7y ago
We considered listing implementations we tested and deemed secure, however this is really hard to do in practice. See also the answer in the second question in the Q&A. Most libraries have several implementations of the scalar multiplic
6.
▲
Minerva: Practically exploitable side-channel leakage in ECDSA implementations
(minerva.crocs.fi.muni.cz)
85 points
by
j08ny
7y ago
|
50 comments
7.
▲
by
j08ny
9y ago
It's not practical for most cases, but the few very very high-security ones. The pads are distributed beforehand, stored securely and used when a message encrypted to them comes in. So it's just that the message can have OTP secur
8.
▲
The Theoretical Minimum
(theoreticalminimum.com)
2 points
by
j08ny
9y ago
|
0 comments