[108667] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: fyi: Adi Shamir's microprocessor bug attack

daemon@ATHENA.MIT.EDU (Florian Weimer)
Wed Nov 21 23:13:03 2007

From: Florian Weimer <fw@deneb.enyo.de>
To: ' =JeffH ' <Jeff.Hodges@KingsMountain.com>
Cc: cryptography@metzdowd.com
Date: Tue, 20 Nov 2007 09:41:43 +0100
In-Reply-To: <20071117192508.911C7E7C2DD@networking.stanford.edu> (JeffH's
	message of "Sat, 17 Nov 2007 11:25:08 -0800")

Perhaps I'm missing something, but real-world RSA implementations are
not vulnerable to this because they implement RSA blinding to prevent
timing attacks (which prevents a magic a * b fault from being exploited
deterministically) or verify the signature after creation (which
protects against random faults, a very good idea anyway).

Something can't be "new" and "big" if it's been addressed in GnuPG,
Crypto++ and others years ago. 8-P

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post