On validating Curve25519 public keys, by @veorq https://research.kudelskisecurity.com/2017/04/25/should-ecdh-keys-be-validated/ …
-
-
Replying to @matthew_d_green @veorq
The first thing you learn in any crypto class is to forget anything else you think you know. Padding oracles come to mind.pic.twitter.com/q8CBeT2vQw
2 replies 7 retweets 21 likes -
Replying to @marcan42 @matthew_d_green
So what? Invalid padding rejected anyway
1 reply 0 retweets 2 likes -
Replying to @veorq @matthew_d_green
Sometimes rejecting things early or in a different way introduces security vulnerabilities. Crypto != application logic.
2 replies 0 retweets 2 likes -
i'd figure comparing against 0 in fixed time wouldn't be so tricky
1 reply 0 retweets 5 likes
It's not just about fixed time. Also, I'm not saying it's difficult or a bad idea in *this* case. I'm just rejecting that blanket argument.
1:00 PM - 25 Apr 2017
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.