[108816] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: fyi: Adi Shamir's microprocessor bug attack

daemon@ATHENA.MIT.EDU (James A. Donald)
Fri Nov 23 09:00:46 2007

Date: Fri, 23 Nov 2007 09:39:56 +1000
From: "James A. Donald" <jamesd@echeque.com>
To: James Muir <jamuir@cs.smu.ca>
CC: cryptography@metzdowd.com
In-Reply-To: <4741F1B1.8070906@cs.smu.ca>

James Muir wrote:
 > Can anyone think of a deployed implementation of RSA
 > signatures that would be vulnerable to the attack
 > Shamir mentions?  Hashing and message blinding would
 > seem to thwart it.

As I said, public key encryption has long been known to
be weak against chosen plaintext and chosen cryptotext -
so protocols have long been designed to prevent this
sort of attack.  If they are not so designed, they were
known to be weak before this attack was discovered.

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post