On validating Curve25519 public keys, by @veorq https://research.kudelskisecurity.com/2017/04/25/should-ecdh-keys-be-validated/ …
-
-
So what? Invalid padding rejected anyway
-
Sometimes rejecting things early or in a different way introduces security vulnerabilities. Crypto != application logic.
- Show replies
New conversation -
-
-
no, that's exactly how you do it if you use a proper aead. the problem with padding oracles is subtle, but due to bad alg choices.
-
you should reject invalid input, but the very first check you should do is that the content hasn't been attacker-modified.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.