[108666] in cryptography@c2.net mail archive
Re: fyi: Adi Shamir's microprocessor bug attack
daemon@ATHENA.MIT.EDU (James Muir)
Wed Nov 21 23:12:16 2007
Date: Mon, 19 Nov 2007 16:27:29 -0400
From: James Muir <jamuir@cs.smu.ca>
To: cryptography@metzdowd.com
In-Reply-To: <20071117192508.911C7E7C2DD@networking.stanford.edu>
' =JeffH ' wrote:
> From: John Young <cryptome@earthlink.net>
> Subject: Adi Shamir's microprocessor bug attack
> To: ukcrypto@chiark.greenend.org.uk
> Date: Sat, 17 Nov 2007 09:50:31 -0500 (GMT-05:00)
>
>
> Adi Shamir's note on a microprocessor bug attack on public key cryptography
> featured in the NY Times today:
>
> http://cryptome.org/bug-attack.htm
>
> The NYT report:
>
> http://www.nytimes.com/2007/11/17/technology/17code.html
>
Can anyone think of a deployed implementation of RSA signatures that
would be vulnerable to the attack Shamir mentions? Hashing and message
blinding would seem to thwart it.
Incidentally, in the 2001 Boneh-DeMillo-Lipton paper they do mention the
Intel floating point division bug.
-James
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com