[108666] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: fyi: Adi Shamir's microprocessor bug attack

daemon@ATHENA.MIT.EDU (James Muir)
Wed Nov 21 23:12:16 2007

Date: Mon, 19 Nov 2007 16:27:29 -0400
From: James Muir <jamuir@cs.smu.ca>
To: cryptography@metzdowd.com
In-Reply-To: <20071117192508.911C7E7C2DD@networking.stanford.edu>

' =JeffH ' wrote:
> From: John Young <cryptome@earthlink.net>
> Subject: Adi Shamir's microprocessor bug attack
> To: ukcrypto@chiark.greenend.org.uk
> Date: Sat, 17 Nov 2007 09:50:31 -0500 (GMT-05:00)
> 
> 
> Adi Shamir's note on a microprocessor bug attack on public key cryptography 
> featured in the NY Times today:
> 
> http://cryptome.org/bug-attack.htm
> 
> The NYT report:
> 
> http://www.nytimes.com/2007/11/17/technology/17code.html
> 

Can anyone think of a deployed implementation of RSA signatures that 
would be vulnerable to the attack Shamir mentions?  Hashing and message 
blinding would seem to thwart it.

Incidentally, in the 2001 Boneh-DeMillo-Lipton paper they do mention the 
Intel floating point division bug.

-James

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post